CVE-2015-0669
published 2015-03-21CVE-2015-0669: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15.4S and 15.4(3)S allows remote attackers to modify configuration settings or cause…
PriorityP431medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
1.73%
75.3th percentile
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15.4S and 15.4(3)S allows remote attackers to modify configuration settings or cause a denial of service (partial service outage) by sending crafted Autonomic Networking (AN) messages on an intranet network, aka Bug ID CSCup62167.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Autonomic Networking Infrastructure Overwrite Vulnerability
vendor_cisco·2015-03-19·CVSS 6.4
CVE-2015-0669 [MEDIUM] CWE-20 Cisco IOS Software Autonomic Networking Infrastructure Overwrite Vulnerability
Cisco IOS Software Autonomic Networking Infrastructure Overwrite Vulnerability
A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS software could allow an unauthenticated, remote attacker to overwrite some configuration values received via ANI.
The vulnerability is due to insufficient validation of received
Autonomic Networking (AN) messages. An attacker could exploit this
vulnerability by sending crafted AN messages. An exploit could allow the attacker to overwrite sensitive configuration and cause a partial denial of service (DoS) condition. A limited set of router services can be affected.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks beh
GHSA
GHSA-wc6h-7fpv-2vw4: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-0669 [MEDIUM] CWE-20 GHSA-wc6h-7fpv-2vw4: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15.4S and 15.4(3)S allows remote attackers to modify configuration settings or cause a denial of service (partial service outage) by sending crafted Autonomic Networking (AN) messages on an intranet network, aka Bug ID CSCup62167.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-03-21
Published