CVE-2015-4200
published 2015-06-23CVE-2015-4200: Memory leak in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.46%
87.8th percentile
Memory leak in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (memory consumption) by triggering an error during CPE negotiation, aka Bug ID CSCug00885.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software UBR Devices IPv6 to IPv4 Subsystem Denial of Service Vulnerability
vendor_cisco·2015-06-22·CVSS 7.8
CVE-2015-4200 [HIGH] CWE-399 Cisco IOS Software UBR Devices IPv6 to IPv4 Subsystem Denial of Service Vulnerability
Cisco IOS Software UBR Devices IPv6 to IPv4 Subsystem Denial of Service Vulnerability
A vulnerability in the IPv6 to IPv4 subsystem of Cisco IOS Software could allow an unauthenticated, remote attacker to cause a standby Performance Routing Engine (PRE) to leak a small portion of memory on a targeted system, resulting in a denial of service (DoS) condition.
The vulnerability is due to a failure to free a portion of memory allocated to store the IPv6 address of a connecting customer premises equipment (CPE) device when a specific error condition is encountered. An attacker who can trigger a specific type of failed CPE negotiation could cause the standby PRE to leak a small portion of memory, resulting in a DoS condition.
Cisco has confirmed the vulnerability and released software updates
GHSA
GHSA-5r6c-r963-4qqw: Memory leak in the IPv6-to-IPv4 functionality in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-4200 [HIGH] GHSA-5r6c-r963-4qqw: Memory leak in the IPv6-to-IPv4 functionality in Cisco IOS 15
Memory leak in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (memory consumption) by triggering an error during CPE negotiation, aka Bug ID CSCug00885.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-23
Published