CVE-2015-4191
published 2015-06-19CVE-2015-4191: Cisco IOS XR 5.2.1 allows remote attackers to cause a denial of service (ipv6_io service reload) via a malformed IPv6 packet, aka Bug ID CSCuq95565.
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.96%
85.8th percentile
Cisco IOS XR 5.2.1 allows remote attackers to cause a denial of service (ipv6_io service reload) via a malformed IPv6 packet, aka Bug ID CSCuq95565.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR IPv6 Packet Processing Denial of Service Vulnerability
vendor_cisco·2015-06-17·CVSS 5.0
CVE-2015-4191 [MEDIUM] CWE-399 Cisco IOS XR IPv6 Packet Processing Denial of Service Vulnerability
Cisco IOS XR IPv6 Packet Processing Denial of Service Vulnerability
A vulnerability in IP version 6 (IPv6) processing in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a reload of the ipv6_io service.
The vulnerability is due to improper processing of a malformed IPv6 packet by a device configured to process such packets. An attacker could exploit this vulnerability by sending a malformed IPv6 packet to be processed by a device that is configured for IPv6. An exploit could allow the attacker to cause a reload of the ipv6_io service.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker may need to acquire additional information about the targeted device, such as whether the device is configured t
GHSA
GHSA-574v-ffv3-5fcx: Cisco IOS XR 5
ghsa_unreviewed·2022-05-17
CVE-2015-4191 [MEDIUM] GHSA-574v-ffv3-5fcx: Cisco IOS XR 5
Cisco IOS XR 5.2.1 allows remote attackers to cause a denial of service (ipv6_io service reload) via a malformed IPv6 packet, aka Bug ID CSCuq95565.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-19
Published