CVE-2015-6256
published 2015-08-22CVE-2015-6256: Cisco ASR 5000 devices with software 19.0.M0.60828 allow remote attackers to cause a denial of service (OSPF process restart) via crafted length fields in…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.46%
70.5th percentile
Cisco ASR 5000 devices with software 19.0.M0.60828 allow remote attackers to cause a denial of service (OSPF process restart) via crafted length fields in headers of OSPF packets, aka Bug ID CSCuv62820.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asr_5000_series_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Aggregation Services Router ASR 5000 and ASR 5500 OSPF Denial of Service Vulnerability
vendor_cisco·2015-08-20·CVSS 5.0
CVE-2015-6256 [MEDIUM] CWE-20 Cisco Aggregation Services Router ASR 5000 and ASR 5500 OSPF Denial of Service Vulnerability
Cisco Aggregation Services Router ASR 5000 and ASR 5500 OSPF Denial of Service Vulnerability
A vulnerability in the Open Shortest Path First (OSPF) protocol implementation of the Cisco Aggregation Services Router (ASR) 5000 and ASR 5500 System Software could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition because the OSPF process restarts.
The vulnerability is due to improper input validation of the length fields in the OSPF packet header. An attacker could exploit this vulnerability by sending crafted OSPF packets to the device. An exploit could allow the attacker to cause a partial DoS condition because the OSPF process could restart when parsing the crafted OSPF packet.
Cisco has confirmed the vulnerability and released software updates.
GHSA
GHSA-656p-93mq-rx8g: Cisco ASR 5000 devices with software 19
ghsa_unreviewed·2022-05-17
CVE-2015-6256 [MEDIUM] CWE-20 GHSA-656p-93mq-rx8g: Cisco ASR 5000 devices with software 19
Cisco ASR 5000 devices with software 19.0.M0.60828 allow remote attackers to cause a denial of service (OSPF process restart) via crafted length fields in headers of OSPF packets, aka Bug ID CSCuv62820.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-22
Published