CVE-2015-0710
published 2015-04-29CVE-2015-0710: The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a…
PriorityP424medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
0.72%
50.2th percentile
The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a series of packets that are considered oversized and trigger improper fragmentation handling, aka Bug IDs CSCup37676 and CSCup30335.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cq2f-mgf9-68xr: The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3
ghsa_unreviewed·2022-05-17
CVE-2015-0710 [MEDIUM] GHSA-cq2f-mgf9-68xr: The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3
The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a series of packets that are considered oversized and trigger improper fragmentation handling, aka Bug IDs CSCup37676 and CSCup30335.
Cisco
Cisco IOS XE Software OTV Processing Code Denial of Service Vulnerability
vendor_cisco·2015-04-28·CVSS 6.1
CVE-2015-0710 [MEDIUM] CWE-399 Cisco IOS XE Software OTV Processing Code Denial of Service Vulnerability
Cisco IOS XE Software OTV Processing Code Denial of Service Vulnerability
A vulnerability in the Overlay Transport Virtualization (OTV) processing code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a reload of the affected device.
The vulnerability is due to improper processing of oversized OTV frames passing through an affected device. An attacker could exploit this vulnerability by sending a number of packets that are processed as oversized OTV frames that may require fragmentation and reassembly by an affected device. An exploit could allow the attacker to cause a reload of the affected device.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must be on the same broadcast or collisi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-29
Published