CVE-2015-4273Improper Input Validation in Cisco ASR 5000 Series Software

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 36.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 17

Description

The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15.0(912), 15.0(935), and 15.0(938) allows remote attackers to cause a denial of service (Session Manager outage) via malformed fields in an IP packet, aka Bug ID CSCut38476.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDcisco/asr_5000_series_software15.0\(912\), 15.0\(935\), 15.0\(938\)+2

🔴Vulnerability Details

2
GHSA
GHSA-pvwc-h4wp-xc77: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 152022-05-17
CVEList
CVE-2015-4273: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 152015-07-15

📋Vendor Advisories

1
Cisco
Cisco Packet Data Network Gateway IP Stack Denial of Service Vulnerability2015-07-14
CVE-2015-4273 — Improper Input Validation in Cisco | cvebase