CVE-2015-6297
published 2015-09-18CVE-2015-6297: The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.44%
82.6th percentile
The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4x2j-vmv4-3qc3: The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5
ghsa_unreviewed·2022-05-17
CVE-2015-6297 [MEDIUM] GHSA-4x2j-vmv4-3qc3: The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5
The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.
Cisco
Cisco IOS Software DHCPv6 Server Implementation Denial of Service Vulnerability
vendor_cisco·2015-09-18·CVSS 5.0
CVE-2015-6297 [MEDIUM] CWE-399 Cisco IOS Software DHCPv6 Server Implementation Denial of Service Vulnerability
Cisco IOS Software DHCPv6 Server Implementation Denial of Service Vulnerability
A vulnerability in the DHCP version 6 (DHCPv6) server implementation of Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of crafted DHCPv6 packets. An attacker could exploit this vulnerability by sending crafted DHCPv6 packets to be processed by the affected device. An exploit could allow the attacker to cause a reset of an affected process.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability a remote attacker does not need to authenticate to pass the crafted DHCPv6 packets to the targeted device. This increases the likelihood of a possible exploit.
C
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-18
Published