CVE-2015-0681Cisco IOS vulnerability

CWE-3994 documents4 sources
Severity
7.1HIGHNVD
EPSS
0.6%
top 31.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 24
Latest updateMay 17

Description

The TFTP server in Cisco IOS 12.2(44)SQ1, 12.2(33)XN1, 12.4(25e)JAM1, 12.4(25e)JAO5m, 12.4(23)JY, 15.0(2)ED1, 15.0(2)EY3, 15.1(3)SVF4a, and 15.2(2)JB1 and IOS XE 2.5.x, 2.6.x, 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, and 3.5.xS before 3.6.0S; 3.1.xSG, 3.2.xSG, and 3.3.xSG before 3.4.0SG; 3.2.xSE before 3.3.0SE; 3.2.xXO before 3.3.0XO; 3.2.xSQ; 3.3.xSQ; and 3.4.xSQ allows remote attackers to cause a denial of service (device hang or reload) via multiple requests that trigger improper memory management, ak

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages2 packages

NVDcisco/ios9 versions+8
NVDcisco/ios_xe53 versions+52

🔴Vulnerability Details

2
GHSA
GHSA-vfp8-xr5w-hr86: The TFTP server in Cisco IOS 122022-05-17
CVEList
CVE-2015-0681: The TFTP server in Cisco IOS 122015-07-24

📋Vendor Advisories

1
Cisco
Cisco IOS Software TFTP Server Denial of Service Vulnerability2015-07-22
CVE-2015-0681 — Cisco IOS vulnerability | cvebase