CVE-2015-4199
published 2015-06-27CVE-2015-4199: Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to…
PriorityP430high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.12%
80.0th percentile
Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity with many IPv6 CPE devices, aka Bug ID CSCug47366.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3422-45qx-4m3x: Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-4199 [HIGH] CWE-362 GHSA-3422-45qx-4m3x: Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15
Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity with many IPv6 CPE devices, aka Bug ID CSCug47366.
Cisco
Cisco IOS Software UBR Devices IPv6 to IPv4 Subsystem Denial of Service Vulnerability
vendor_cisco·2015-06-22·CVSS 7.1
CVE-2015-4199 [HIGH] CWE-362 Cisco IOS Software UBR Devices IPv6 to IPv4 Subsystem Denial of Service Vulnerability
Cisco IOS Software UBR Devices IPv6 to IPv4 Subsystem Denial of Service Vulnerability
A vulnerability in the IPv6 to IPv4 subsystem of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a Performance Routing Engine (PRE) crash on a targeted system, resulting in a denial of service (DoS) condition.
The vulnerability is due to a race condition that may cause a NULL pointer to be freed. An attacker could exploit this vulnerability by submitting crafted content to a targeted device designed to trigger a race condition. A successful exploit could cause a PRE module on the device to crash, resulting in a DoS condition.
Cisco has confirmed the vulnerability and released software updates.
An attacker would need to cause hundreds of IPv6-enabled customer premises equ
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-27
Published