CVE-2015-4205
published 2015-06-23CVE-2015-4205: Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x…
PriorityP424medium5.7CVSS 2.0
AVAACMAuNCNINAC
EPSS
0.87%
55.2th percentile
Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x flow-control PAUSE frames on the local network, aka Bug ID CSCut19959.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.05.7MEDIUMAV:A/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers Denial of Service Vulnerability
vendor_cisco·2015-06-22·CVSS 5.7
CVE-2015-4205 [MEDIUM] CWE-399 Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers Denial of Service Vulnerability
Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers Denial of Service Vulnerability
A vulnerability in flow control processing of Cisco IOS XR Software for Cisco ASR 9000 Series Routers could allow an unauthenticated, adjacent attacker to cause a Network Processing Unit (NPU) chip reset and potentially a reload of the affected line card.
The vulnerability is due to improper processing of crafted IEEE 802.3x flow control pause frames. An attacker could exploit this vulnerability by sending a number of crafted IEEE 802.3x flow control pause frames to an affected device. An exploit could allow the attacker to cause an NPU chip reset and potentially a reload of the affected line card.
Cisco has confirmed the vulnerability and released software updates.
To exploit
GHSA
GHSA-28x7-5mgh-vp76: Cisco IOS XR 5
ghsa_unreviewed·2022-05-17
CVE-2015-4205 [MEDIUM] GHSA-28x7-5mgh-vp76: Cisco IOS XR 5
Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x flow-control PAUSE frames on the local network, aka Bug ID CSCut19959.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-23
Published