CVE-2015-0718

CWE-3996 documents5 sources
Severity
7.5HIGH
EPSS
6.0%
top 9.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3
Latest updateJan 13

Description

Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages7 packages

NVDcisco/unified_computing_system59 versions+58
NVDcisco/nx-osbase
NVDnetgear/jr6150_firmware< 2017-01-06
NVDzyxel/gs1900-10hp_firmware< 2.50\(aazi.0\)c0
NVDsun/opensolarissnv_124

🔴Vulnerability Details

4
OSV
libxmltok vulnerabilities2025-01-13
OSV
libxmltok vulnerabilities2022-07-19
GHSA
GHSA-858m-ch9v-jg28: Cisco NX-OS 42022-05-17
CVEList
CVE-2015-0718: Cisco NX-OS 42016-03-03

📋Vendor Advisories

1
Cisco
Cisco NX-OS Software TCP Netstack Denial of Service Vulnerability2016-03-03