CVE-2015-0712
published 2015-05-01CVE-2015-0712: The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attackers to cause a denial of service…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.24%
65.7th percentile
The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and packet loss) via malformed HTTP packets, aka Bug ID CSCud14217.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | staros | — | — |
| cisco | staros | — | — |
| cisco | staros | — | — |
| cisco | staros | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco StarOS for Cisco ASR 5000 Series HTTP Packet Processing Denial of Service Vulnerability
vendor_cisco·2015-04-29·CVSS 5.0
CVE-2015-0712 [MEDIUM] CWE-399 Cisco StarOS for Cisco ASR 5000 Series HTTP Packet Processing Denial of Service Vulnerability
Cisco StarOS for Cisco ASR 5000 Series HTTP Packet Processing Denial of Service Vulnerability
A vulnerability in HTTP packet processing of Cisco StarOS for Cisco ASR 5000 Series devices could allow an unauthenticated, remote attacker to cause a reload of the session manager service on the affected device.
The vulnerability is due to improper processing of malformed HTTP packets. An attacker could exploit this vulnerability by sending a number of malformed HTTP packets to the affected device. An exploit could allow the attacker to cause the session manager service on the device to reload. A reload of the session manager service may cause loss of packets during a recovery period, resulting in a denial of service (DoS) condition.
Cisco has confirmed the vulnerability and released software
GHSA
GHSA-q89c-84wv-f79v: The session-manager service in Cisco StarOS 12
ghsa_unreviewed·2022-05-17
CVE-2015-0712 [MEDIUM] GHSA-q89c-84wv-f79v: The session-manager service in Cisco StarOS 12
The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and packet loss) via malformed HTTP packets, aka Bug ID CSCud14217.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-01
Published