CVE-2015-0688
published 2015-04-04CVE-2015-0688: Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of…
PriorityP430high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.67%
74.4th percentile
Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7mc-88hw-5x8r: Cisco IOS XE 3
ghsa_unreviewed·2022-05-17
CVE-2015-0688 [HIGH] GHSA-c7mc-88hw-5x8r: Cisco IOS XE 3
Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.
Cisco
Cisco ASR1000 Series Routers ESP Module Denial of Service Vulnerability
vendor_cisco·2015-04-03·CVSS 7.1
CVE-2015-0688 [HIGH] CWE-399 Cisco ASR1000 Series Routers ESP Module Denial of Service Vulnerability
Cisco ASR1000 Series Routers ESP Module Denial of Service Vulnerability
A vulnerability in the Embedded Services Processor (ESP) module of Cisco ASR 1000 Series Routers running Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of malformed H.323 packets by an affected device when the device is configured to use Network Address Translation (NAT). An unauthenticated, remote attacker could exploit this vulnerability by sending malformed H.323 packets to a targeted device. A successful exploit could cause the ESP module on the device to crash, resulting in a DoS condition.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an atta
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-04
Published