CVE-2015-0711
published 2015-04-29CVE-2015-0711: The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5000 devices allows remote attackers to cause a denial of…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.76%
75.4th percentile
The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and call-processing outage) via malformed PM packets, aka Bug ID CSCut94711.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | staros | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-27c3-mh68-3469: The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18
ghsa_unreviewed·2022-05-17
CVE-2015-0711 [MEDIUM] GHSA-27c3-mh68-3469: The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18
The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and call-processing outage) via malformed PM packets, aka Bug ID CSCut94711.
Cisco
Cisco StarOS for Cisco ASR 5000 Series HAMGR Service Proxy Mobile IPv6 Processing Denial of Service Vulnerability
vendor_cisco·2015-04-28·CVSS 5.0
CVE-2015-0711 [MEDIUM] CWE-399 Cisco StarOS for Cisco ASR 5000 Series HAMGR Service Proxy Mobile IPv6 Processing Denial of Service Vulnerability
Cisco StarOS for Cisco ASR 5000 Series HAMGR Service Proxy Mobile IPv6 Processing Denial of Service Vulnerability
A vulnerability in proxy mobile (PM) IPv6 processing of Cisco StarOS for Cisco ASR 5000 Series devices could allow an unauthenticated, remote attacker to cause a reload of the hamgr service on the affected device.
The vulnerability is due to improper processing of malformed IPv6 PM packets. An attacker could exploit this vulnerability by sending a number of malformed IPv6 PM packets to an affected device. An exploit could allow the attacker to cause the hamgr service on the affected device to reload. A reload of the hamgr service may cause new calls to fail during a recovery period, resulting in a denial of service (DoS) condition.
Cisco has confirmed the vulnerability and r
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-29
Published