CVE-2015-4273
published 2015-07-15CVE-2015-4273: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15.0(912), 15.0(935), and 15.0(938) allows remote attackers to…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.99%
78.3th percentile
The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15.0(912), 15.0(935), and 15.0(938) allows remote attackers to cause a denial of service (Session Manager outage) via malformed fields in an IP packet, aka Bug ID CSCut38476.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Packet Data Network Gateway IP Stack Denial of Service Vulnerability
vendor_cisco·2015-07-14·CVSS 5.0
CVE-2015-4273 [MEDIUM] CWE-20 Cisco Packet Data Network Gateway IP Stack Denial of Service Vulnerability
Cisco Packet Data Network Gateway IP Stack Denial of Service Vulnerability
A vulnerability in the IP stack of the Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) of the Session Manager service when a malformed IP packet is received.
The vulnerability is due to improper input validation of certain fields in the IP packet. An attacker could exploit this vulnerability by crafting a malformed IP packet and sending it to the affected device. An exploit could allow the attacker to cause a DoS of the Session Manager service of the PGW.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must be able to send malformed IP packets to the targeted device,
GHSA
GHSA-pvwc-h4wp-xc77: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15
ghsa_unreviewed·2022-05-17
CVE-2015-4273 [MEDIUM] CWE-20 GHSA-pvwc-h4wp-xc77: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15
The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15.0(912), 15.0(935), and 15.0(938) allows remote attackers to cause a denial of service (Session Manager outage) via malformed fields in an IP packet, aka Bug ID CSCut38476.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-15
Published