CVE-2015-4201
published 2015-06-20CVE-2015-4201: The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.96%
85.6th percentile
The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header, aka Bug ID CSCut68058.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g9cj-g4rw-3p5m: The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17
ghsa_unreviewed·2022-05-17
CVE-2015-4201 [MEDIUM] CWE-20 GHSA-g9cj-g4rw-3p5m: The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17
The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header, aka Bug ID CSCut68058.
Cisco
Cisco Gateway GPRS Support Node TCP Invalid Packet Vulnerability
vendor_cisco·2015-06-19·CVSS 5.0
CVE-2015-4201 [MEDIUM] CWE-20 Cisco Gateway GPRS Support Node TCP Invalid Packet Vulnerability
Cisco Gateway GPRS Support Node TCP Invalid Packet Vulnerability
A vulnerability in the TCP packet input handler of the Cisco Gateway GPRS Support Node (GGSN) could allow an unauthenticated, remote attacker to cause a reset of the Session Manager application.
The vulnerability is due to improper input validation of the length fields of the TCP/IP header. An attacker could exploit this vulnerability by sending a crafted TCP packet with an invalid TCP/IP header. A successful exploit could allow the attacker to cause the Session Manager application on an affected device to restart, resulting in a DoS condition.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, the attacker must send a crafted TCP packet with an invalid TCP/IP header to th
No detection rules found.
No writeups or analysis indexed.
2015-06-20
Published