CVE-2015-4243Cisco IOS XE vulnerability

CWE-3994 documents4 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 50.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 8
Latest updateMay 17

Description

The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty94202.

CVSS vector

AV:A/AC:L/C:N/I:N/A:CExploitability: 6.5 | Impact: 6.9

Affected Packages1 packages

NVDcisco/ios_xe3.5.0s

🔴Vulnerability Details

2
GHSA
GHSA-xmx7-4wwc-55h4: The PPPoE establishment implementation in Cisco IOS XE 32022-05-17
CVEList
CVE-2015-4243: The PPPoE establishment implementation in Cisco IOS XE 32015-07-08

📋Vendor Advisories

1
Cisco
Cisco IOS XE for Cisco 1000 Series ASR Routers Denial of Service Vulnerability2015-07-07
CVE-2015-4243 — Cisco IOS XE vulnerability | cvebase