CVE-2015-6277
published 2015-09-02CVE-2015-6277: The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1…
PriorityP426medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
0.89%
55.5th percentile
The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1, Nexus 9000 devices 7.3(0)ZD(0.61), and MDS 9000 devices 7.0(0)HSK(0.353) and SAN-OS NX-OS on MDS 9000 devices 7.0(0)HSK(0.353) allows remote attackers to cause a denial of service (ARP process restart) via crafted packet-header fields, aka Bug ID CSCut25292.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | 1000v | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | san-os | — | — |
CVSS provenance
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mgmf-hg59-85fw: The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5
ghsa_unreviewed·2022-05-17
CVE-2015-6277 [MEDIUM] GHSA-mgmf-hg59-85fw: The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5
The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1, Nexus 9000 devices 7.3(0)ZD(0.61), and MDS 9000 devices 7.0(0)HSK(0.353) and SAN-OS NX-OS on MDS 9000 devices 7.0(0)HSK(0.353) allows remote attackers to cause a denial of service (ARP process restart) via crafted packet-header fields, aka Bug ID CSCut25292.
Cisco
Cisco NX-OS Malformed ARP Header Denial of Service Vulnerability
vendor_cisco·2015-09-01·CVSS 6.1
CVE-2015-6277 [MEDIUM] CWE-399 Cisco NX-OS Malformed ARP Header Denial of Service Vulnerability
Cisco NX-OS Malformed ARP Header Denial of Service Vulnerability
A vulnerability in Address Resolution Protocol (ARP) feature of the Cisco Nexus Operating System (NX-OS) could allow an unauthenticated, adjacent attacker to cause a partial denial of service (DoS) condition because the ARP process unexpectedly restarts.
The vulnerability is due to improper input validation of the fields in the ARP packet header. An attacker could exploit this vulnerability by sending a crafted ARP packet from an adjacent network to the affected device. An exploit could allow the attacker to cause a partial DoS condition because the ARP process could unexpectedly restart when processing the crafted ARP packet.
Cisco has confirmed the vulnerability and software updates are available.
To exploit this vulne
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-02
Published