CVE-2015-4223
published 2015-06-25CVE-2015-4223: Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.48%
82.9th percentile
Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8mr-3p5f-7x8h: Cisco IOS XR 5
ghsa_unreviewed·2022-05-17
CVE-2015-4223 [MEDIUM] GHSA-w8mr-3p5f-7x8h: Cisco IOS XR 5
Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478.
Cisco
Cisco IOS XR MPLS LDP Packet Processing Denial of Service Vulnerability
vendor_cisco·2015-06-24·CVSS 5.0
CVE-2015-4223 [MEDIUM] CWE-399 Cisco IOS XR MPLS LDP Packet Processing Denial of Service Vulnerability
Cisco IOS XR MPLS LDP Packet Processing Denial of Service Vulnerability
A vulnerability in the Multiprotocol Label Switching (MPLS) Label Distribution Protocol (LDP) packet processing feature of Cisco IOS XR could allow an unauthenticated, remote attacker to cause a reload of the MPLS LDP process on the affected device.
The vulnerability is due to improper processing of crafted MPLS LDP packets. An attacker could exploit this vulnerability by sending crafted MPLS LDP packets to be processed by an affected device. An exploit could allow the attacker to cause a reload of the MPLS LDP process on the affected device.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker may need to acquire additional information about the targeted
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-25
Published