CVE-2015-4202
published 2015-06-20CVE-2015-4202: Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service, which…
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.81%
76.0th percentile
Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service, which allows remote attackers to obtain potentially sensitive MAC address and network-utilization information via crafted IPDR packets, aka Bug ID CSCua39203.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4mf4-pwvw-5252: Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2015-4202 [MEDIUM] CWE-200 GHSA-4mf4-pwvw-5252: Cisco IOS 12
Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service, which allows remote attackers to obtain potentially sensitive MAC address and network-utilization information via crafted IPDR packets, aka Bug ID CSCua39203.
Cisco
Cisco uBR10000 Series Universal Broadband Routers Information Disclosure Vulnerability
vendor_cisco·2015-06-19·CVSS 5.0
CVE-2015-4202 [MEDIUM] CWE-200 Cisco uBR10000 Series Universal Broadband Routers Information Disclosure Vulnerability
Cisco uBR10000 Series Universal Broadband Routers Information Disclosure Vulnerability
A vulnerability in the processing of IP Detail Record (IPDR) packets on Cisco uBR10000 devices could allow an unauthenticated, remote attacker to gather a limited amount of IPDR data from the affected device.
The vulnerability is due to the inability of Cisco Cable Modem Termination Systems (CMTS) to define access control lists (ACLs) specific to the IPDR service to block unauthorized users. An attacker could exploit this vulnerability by sending crafted IPDR packets requesting that a limited amount of information from an affected CMTS is exported back to the attacker's IP address. A successful exploit could allow the attacker to gather a limited amount of IPDR data from the affected device.
Cisco has
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-20
Published