CVE-2015-6294
published 2015-09-18CVE-2015-6294: Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (functionality loss) via crafted Cisco…
PriorityP422medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
0.77%
51.4th percentile
Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (functionality loss) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuu25770.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Cisco Discovery Protocol Packet Processing Denial of Service Vulnerability
vendor_cisco·2015-09-17·CVSS 6.1
CVE-2015-6294 [MEDIUM] CWE-399 Cisco IOS XE Cisco Discovery Protocol Packet Processing Denial of Service Vulnerability
Cisco IOS XE Cisco Discovery Protocol Packet Processing Denial of Service Vulnerability
A vulnerability in Cisco Catalyst 4500 Series Switches running Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to improper processing of valid crafted Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol packets to be processed by an affected device. An exploit could allow the attacker to cause the software to stop functioning properly, resulting in a DoS condition on the affected device.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker may need to acqu
GHSA
GHSA-m8c9-qwx9-gjr5: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-6294 [MEDIUM] GHSA-m8c9-qwx9-gjr5: Cisco IOS 15
Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (functionality loss) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuu25770.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-18
Published