CVE-2015-0771
published 2015-06-12CVE-2015-0771: The IKE implementation in the WS-IPSEC-3 service module in Cisco IOS 12.2 on Catalyst 6500 devices allows remote authenticated users to cause a denial of…
PriorityP429medium6.3CVSS 2.0
AVNACMAuSCNINAC
EPSS
2.42%
82.5th percentile
The IKE implementation in the WS-IPSEC-3 service module in Cisco IOS 12.2 on Catalyst 6500 devices allows remote authenticated users to cause a denial of service (device reload) by sending a crafted message during IPsec tunnel setup, aka Bug ID CSCur70505.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| samba | samba | >= 0 < 2:4.1.6+dfsg-1ubuntu2.14.04.13 | 2:4.1.6+dfsg-1ubuntu2.14.04.13 |
CVSS provenance
nvdv2.06.3MEDIUMAV:N/AC:M/Au:S/C:N/I:N/A:C
osv5.1MEDIUM
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvpv-pjqh-3r46: The IKE implementation in the WS-IPSEC-3 service module in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2015-0771 [MEDIUM] GHSA-fvpv-pjqh-3r46: The IKE implementation in the WS-IPSEC-3 service module in Cisco IOS 12
The IKE implementation in the WS-IPSEC-3 service module in Cisco IOS 12.2 on Catalyst 6500 devices allows remote authenticated users to cause a denial of service (device reload) by sending a crafted message during IPsec tunnel setup, aka Bug ID CSCur70505.
OSV
samba vulnerabilities
osv·2016-03-08·CVSS 5.1
CVE-2015-7560 samba vulnerabilities
samba vulnerabilities
Jeremy Allison discovered that Samba incorrectly handled ACLs on symlink
paths. A remote attacker could use this issue to overwrite the ownership of
ACLs using symlinks. (CVE-2015-7560)
Garming Sam and Douglas Bagnall discovered that the Samba internal DNS
server incorrectly handled certain DNS TXT records. A remote attacker could
use this issue to cause Samba to crash, resulting in a denial of service,
or possibly obtain uninitialized memory contents. This issue only applied
to Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2016-0771)
It was discovered that the Samba Web Administration Tool (SWAT) was
vulnerable to clickjacking and cross-site request forgery attacks. This
issue only affected Ubuntu 12.04 LTS. (CVE-2013-0213, CVE-2013-0214)
Cisco
Cisco Catalyst 6500 Series Switches IPsec Tunnel Handling Denial of Service Vulnerability
vendor_cisco·2015-06-08·CVSS 6.3
CVE-2015-0771 [MEDIUM] CWE-399 Cisco Catalyst 6500 Series Switches IPsec Tunnel Handling Denial of Service Vulnerability
Cisco Catalyst 6500 Series Switches IPsec Tunnel Handling Denial of Service Vulnerability
A vulnerability in the Internet Key Exchange (IKE) subsystem of the Cisco WS-IPSEC-3 service module could allow an authenticated, remote attacker to cause a reload of the Catalyst switch.
The vulnerability is due to insufficient bounds checks on a specific message during the establishment of an IPsec tunnel. An attacker could exploit this vulnerability by establishing an IKE session and sending the offending packet during subsequent negotiations. An exploit could allow the attacker to cause a denial of service by forcibly reloading the switch.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, an attacker must authenticate to the tar
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-12
Published