CVE-2015-4204
published 2015-06-23CVE-2015-4204: Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authenticated users to cause a denial of service…
PriorityP426medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
2.74%
84.6th percentile
Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authenticated users to cause a denial of service (memory consumption or PXF process crash) by sending docsIfMCmtsMib SNMP requests quickly, aka Bug ID CSCue65051.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios | — | — |
| cisco | cisco_ios | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vj5g-jj63-gm6r: Memory leak in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2015-4204 [MEDIUM] GHSA-vj5g-jj63-gm6r: Memory leak in Cisco IOS 12
Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authenticated users to cause a denial of service (memory consumption or PXF process crash) by sending docsIfMCmtsMib SNMP requests quickly, aka Bug ID CSCue65051.
Cisco
Cisco IOS Software UBR Devices SNMP Subsystem Denial of Service Vulnerability
vendor_cisco·2015-06-22·CVSS 6.8
CVE-2015-4204 [MEDIUM] CWE-399 Cisco IOS Software UBR Devices SNMP Subsystem Denial of Service Vulnerability
Cisco IOS Software UBR Devices SNMP Subsystem Denial of Service Vulnerability
A vulnerability in the SNMP subsystem of Cisco Universal Broadband Router devices could allow an authenticated, remote attacker to cause a crash of the Parallel Express Forwarding (PXF) process on the Performance Routing Engine (PRE) module.
The vulnerability is due to a memory leak that occurs when certain values in docsIfMCmtsMib are polled via SNMP. An attacker who can authenticate and submit SNMP requests to an affected device could poll the affected element at a high rate and quickly exhaust process memory, resulting in a crash.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement
No detection rules found.
Nuclei
Swim Team <= v1.44.10777 - Local File Inclusion
nuclei·CVSS 5.3
CVE-2015-5471 [MEDIUM] Swim Team <= v1.44.10777 - Local File Inclusion
Swim Team <= v1.44.10777 - Local File Inclusion
The program /wp-swimteam/include/user/download.php allows unauthenticated attackers to retrieve arbitrary files from the system.
Template:
id: CVE-2015-5471
info:
name: Swim Team <= v1.44.10777 - Local File Inclusion
author: 0x_Akoko
severity: medium
description: The program /wp-swimteam/include/user/download.php allows unauthenticated attackers to retrieve arbitrary files from the system.
impact: |
An attacker can exploit this vulnerability to read sensitive information from the server, such as database credentials, and potentially execute arbitrary code.
remediation: Upgrade to Swim Team version 1.45 or newer.
reference:
- https://wpscan.com/vulnerability/b00d9dda-721d-4204-8995-093f695c3568
- http://www.vapid.dhs.org/advisory.php?v=134
No writeups or analysis indexed.
2015-06-23
Published