CVE-2015-4285
published 2015-07-23CVE-2015-4285: The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.74%
75.4th percentile
The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports continuously, aka Bug ID CSCur88273.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fx7w-42hf-7jg6: The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5
ghsa_unreviewed·2022-05-17
CVE-2015-4285 [MEDIUM] GHSA-fx7w-42hf-7jg6: The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5
The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports continuously, aka Bug ID CSCur88273.
Cisco
Cisco IOS XR LPTS Network Stack Remote Denial of Service Vulnerability
vendor_cisco·2015-07-22·CVSS 5.0
CVE-2015-4285 [MEDIUM] CWE-399 Cisco IOS XR LPTS Network Stack Remote Denial of Service Vulnerability
Cisco IOS XR LPTS Network Stack Remote Denial of Service Vulnerability
A vulnerability in the Local Packet Transport Services (LPTS) network stack of Cisco IOS XR for Cisco ASR9k could allow an unauthenticated, remote attacker to cause a limited denial of service (DoS) condition on an affected platform.
The vulnerability is due to improper handling of flow base entries by LPTS that can cause some TCP and UDP ports to be erroneously opened for network access. An attacker could exploit this vulnerability by sending continuous connection attempts to the open ports and cause an exhaustion of services. An exploit could allow the attacker to cause a limited denial of service (DoS) condition on an affected platform.
Cisco has confirmed the vulnerability and released software updates.
Only de
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-23
Published