CVE-2015-4275

CWE-3994 documents4 sources
Severity
5.0MEDIUM
EPSS
0.5%
top 35.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateMay 17

Description

The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 18.0.0.59167 and 18.0.0.59211 allows remote attackers to cause a denial of service via a malformed header in a GTPv2 packet, aka Bug ID CSCut11534.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDcisco/asr_5000_series_software18.0.0.59167, 18.0.0.59211+1

🔴Vulnerability Details

2
GHSA
GHSA-xx9j-qj8x-mmv5: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 182022-05-17
CVEList
CVE-2015-4275: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 182015-07-16

📋Vendor Advisories

1
Cisco
Cisco Packet Data Network Gateway GTPv2 Tunnel Vulnerability2015-07-15
CVE-2015-4275 (MEDIUM CVSS 5) | The Packet Data Network Gateway (ak | cvebase.io