CVE-2015-4195
published 2015-06-19CVE-2015-4195: Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.65%
74.0th percentile
Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3cv5-693m-8vg4: Cisco IOS XR 5
ghsa_unreviewed·2022-05-17
CVE-2015-4195 [MEDIUM] GHSA-3cv5-693m-8vg4: Cisco IOS XR 5
Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.
Cisco
Cisco IOS XR SSH Disconnect Error Denial of Service Vulnerability
vendor_cisco·2015-06-18·CVSS 4.0
CVE-2015-4195 [MEDIUM] CWE-399 Cisco IOS XR SSH Disconnect Error Denial of Service Vulnerability
Cisco IOS XR SSH Disconnect Error Denial of Service Vulnerability
A vulnerability in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to an error that could occur in the affected software when an SSH connection is disconnected from an affected device. An authenticated, remote attacker could exploit the vulnerability to cause the vty to become unreachable and cause further SSH or Telnet connections to the device to fail, resulting in a DoS condition.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement reduces the likelihood of a successful exploit.
Cisco indicates through
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-19
Published