CVE-2015-6289
published 2016-06-23CVE-2015-6289: Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a denial of service (memory consumption) via…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.40%
90.3th percentile
Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets on the SSH port, aka Bug ID CSCuu13476.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios_and_cisco_ios_xe | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS and Cisco IOS XE Software TCP Denial of Service Vulnerability
vendor_cisco·2016-06-20·CVSS 5.0
CVE-2015-6289 [MEDIUM] CWE-399 Cisco IOS and Cisco IOS XE Software TCP Denial of Service Vulnerability
Cisco IOS and Cisco IOS XE Software TCP Denial of Service Vulnerability
A vulnerability in the handling of remote TCP connections in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to low memory.
The vulnerability is due to the handling of out-of-order, or otherwise invalid, TCP packets on a remote connection to an affected device. An attacker could exploit this vulnerability by connecting to the device and then sending crafted TCP packets that are out of order or have invalid flags. An exploit could allow the attacker to cause the device to report low-memory warnings, which could in turn cause a partial DoS condition. This vulnerability was initially found for Secure Shell Host (SSH) remote conn
Cisco
Cisco IOS and Cisco IOS XE Software TCP Denial of Service Vulnerability
vendor_cisco
CVE-2015-6289 Cisco IOS and Cisco IOS XE Software TCP Denial of Service Vulnerability
CVE-2015-6289: Cisco IOS and Cisco IOS XE Software TCP Denial of Service Vulnerability
A vulnerability in the handling of remote TCP connections in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to low memory. The vulnerability is due to the handling of out-of-order, or otherwise invalid, TCP packets on a remote connection to an affected device. An attacker could exploit this vulnerability by connecting to the device and then sending crafted TCP packets that are out of order or have invalid flags. An exploit could allow the attacker to cause the device to report low-memory warnings, which could in turn cause a partial DoS condition. This vulnerability was initially found for Secure Shell Host (SSH
GHSA
GHSA-3g64-fqmg-p75w: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-6289 [HIGH] GHSA-3g64-fqmg-p75w: Cisco IOS 15
Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets on the SSH port, aka Bug ID CSCuu13476.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160620-isrhttp://www.securityfocus.com/bid/91322http://www.securitytracker.com/id/1036141http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160620-isrhttp://www.securityfocus.com/bid/91322http://www.securitytracker.com/id/1036141
2016-06-23
Published