CVE-2015-4275
published 2015-07-16CVE-2015-4275: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 18.0.0.59167 and 18.0.0.59211 allows remote attackers to cause a…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.74%
75.1th percentile
The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 18.0.0.59167 and 18.0.0.59211 allows remote attackers to cause a denial of service via a malformed header in a GTPv2 packet, aka Bug ID CSCut11534.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xx9j-qj8x-mmv5: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 18
ghsa_unreviewed·2022-05-17
CVE-2015-4275 [MEDIUM] GHSA-xx9j-qj8x-mmv5: The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 18
The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 18.0.0.59167 and 18.0.0.59211 allows remote attackers to cause a denial of service via a malformed header in a GTPv2 packet, aka Bug ID CSCut11534.
Cisco
Cisco Packet Data Network Gateway GTPv2 Tunnel Vulnerability
vendor_cisco·2015-07-15·CVSS 5.0
CVE-2015-4275 [MEDIUM] CWE-399 Cisco Packet Data Network Gateway GTPv2 Tunnel Vulnerability
Cisco Packet Data Network Gateway GTPv2 Tunnel Vulnerability
A vulnerability in the GPRS Tunneling Protocol for Version 2 (GTPv2) of the Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to cause partial availability of the GTPv2 service.
The vulnerability is due to lack of input validation of the incoming GTPv2 packet header. An attacker could exploit this vulnerability by sending a crafted, malformed GTPv2 packet to the affected device. An exploit could allow the attacker to cause a partial availability condition of the GTPv2 service.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must be able to send malformed GTPv2 packets to the targeted device, making exploitation more difficul
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-16
Published