CVE-2015-4291
published 2015-08-01CVE-2015-4291: Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor…
PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.98%
78.5th percentile
Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asr_1000_series_aggregation_services_routers_fragmented_packet | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2wp8-8f56-4p9g: Cisco IOS XE 2
ghsa_unreviewed·2022-05-17
CVE-2015-4291 [HIGH] GHSA-2wp8-8f56-4p9g: Cisco IOS XE 2
Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617.
Cisco
Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
vendor_cisco·2015-07-30·CVSS 7.8
CVE-2015-4291 [HIGH] CWE-399 Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
A vulnerability in the code handling the reassembly of fragmented IP version 4 (IPv4) or IP version 6 (IPv6) packets of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a crash of the Embedded Services Processor (ESP) processing the packet.
The vulnerability is due to improper processing of crafted, fragmented packets. An attacker could exploit this vulnerability by sending a crafted sequence of fragmented packets. An exploit could allow the attacker to cause a reload of the affected platform.
Cisco has released software updates that address this vulnerability.
There are no workarounds to mitigate this
Cisco
Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
vendor_cisco
CVE-2015-4291 Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
CVE-2015-4291: Cisco ASR 1000 Series Aggregation Services Routers Fragmented Packet Denial of Service Vulnerability
A vulnerability in the code handling the reassembly of fragmented IP version 4 (IPv4) or IP version 6 (IPv6) packets of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a crash of the Embedded Services Processor (ESP) processing the packet. The vulnerability is due to improper processing of crafted, fragmented packets. An attacker could exploit this vulnerability by sending a crafted sequence of fragmented packets. An exploit could allow the attacker to cause a reload of the affected platform. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-01
Published