CVE-2015-4284
published 2015-07-22CVE-2015-4284: The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.37%
81.9th percentile
The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process reload) via malformed BGPv4 packets, aka Bug ID CSCur70670.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fw8p-7crp-9pw9: The Concurrent Data Management Replication process in Cisco IOS XR 5
ghsa_unreviewed·2022-05-17
CVE-2015-4284 [MEDIUM] CWE-20 GHSA-fw8p-7crp-9pw9: The Concurrent Data Management Replication process in Cisco IOS XR 5
The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process reload) via malformed BGPv4 packets, aka Bug ID CSCur70670.
Cisco
Cisco IOS XR Concurrent Data Management Replication Process BGP Process Denial of Service Vulnerability
vendor_cisco·2015-07-21·CVSS 5.0
CVE-2015-4284 [MEDIUM] CWE-20 Cisco IOS XR Concurrent Data Management Replication Process BGP Process Denial of Service Vulnerability
Cisco IOS XR Concurrent Data Management Replication Process BGP Process Denial of Service Vulnerability
A vulnerability in the Concurrent Data Management Replication process of Cisco IOS XR for ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a reload of the Border Gateway Protocol (BGP) process.
The vulnerability is due to improper processing of malformed BGPv4 packets on an affected device. An attacker could exploit this vulnerability by sending malformed BGPv4 packets to be processed by an affected device. An exploit could allow the attacker to cause a reload of the BGP process.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, the attacker would need to send malformed BGPv4 packe
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-22
Published