CVE-2015-0685
published 2015-04-03CVE-2015-0685: Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device…
PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.90%
77.4th percentile
Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | <= 3.7s.4 | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ASR1000 Series Routers Incomplete or Glean Adjacencies Denial of Service Vulnerability
vendor_cisco·2015-03-31·CVSS 7.8
CVE-2015-0685 [HIGH] CWE-399 Cisco ASR1000 Series Routers Incomplete or Glean Adjacencies Denial of Service Vulnerability
Cisco ASR1000 Series Routers Incomplete or Glean Adjacencies Denial of Service Vulnerability
A vulnerability in Cisco ASR 1000 Series software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper processing of route adjacencies. An attacker could exploit this vulnerability by sending malicious IP packets to an affected device. A successful exploit could allow the attacker to cause the device to stop responding.
Cisco has confirmed the vulnerability and released software updates.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
GHSA
GHSA-3rmr-75jg-fq5f: Cisco IOS XE before 3
ghsa_unreviewed·2022-05-17
CVE-2015-0685 [HIGH] CWE-20 GHSA-3rmr-75jg-fq5f: Cisco IOS XE before 3
Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-03
Published