CVE-2015-6332
published 2015-10-13CVE-2015-6332: Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug ID…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.00%
78.5th percentile
Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug ID CSCuv56830.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_infrastructure | — | — |
| cisco | prime_renegotiation_request | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Renegotiation Request Denial of Service Vulnerability
vendor_cisco·2015-10-09·CVSS 5.0
CVE-2015-6332 [MEDIUM] CWE-399 Cisco Prime Renegotiation Request Denial of Service Vulnerability
Cisco Prime Renegotiation Request Denial of Service Vulnerability
A vulnerability in Cisco Prime could allow a remote, unauthenticated attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of SSL renegotiation requests. An unauthenticated, remote attacker could exploit this vulnerability by sending multiple SSL requests to a targeted system. A successful exploit could cause the system to become unresponsive, resulting in a DoS condition.
Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151008-cpi
Cisco
Cisco Prime Renegotiation Request Denial of Service Vulnerability
vendor_cisco
CVE-2015-6332 Cisco Prime Renegotiation Request Denial of Service Vulnerability
CVE-2015-6332: Cisco Prime Renegotiation Request Denial of Service Vulnerability
A vulnerability in Cisco Prime could allow a remote, unauthenticated attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper handling of SSL renegotiation requests. An unauthenticated, remote attacker could exploit this vulnerability by sending multiple SSL requests to a targeted system. A successful exploit could cause the system to become unresponsive, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCuv56830
GHSA
GHSA-5j25-h4rj-rvr9: Cisco Prime Infrastructure 2
ghsa_unreviewed·2022-05-17
CVE-2015-6332 [MEDIUM] GHSA-5j25-h4rj-rvr9: Cisco Prime Infrastructure 2
Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug ID CSCuv56830.
Suricata
ET EXPLOIT Possible CVE-2014-6332 DECS2
suricata·2015-02-18·CVSS 8.8
CVE-2014-6332 [HIGH] ET EXPLOIT Possible CVE-2014-6332 DECS2
ET EXPLOIT Possible CVE-2014-6332 DECS2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible CVE-2014-6332 DECS2"; flow:established,to_client; file.data; content:"102,117,110,99,116,105,111,110,32,114,117,110,109,117,109,97,97"; classtype:trojan-activity; sid:2020460; rev:5; metadata:created_at 2015_02_18, cve CVE_2014_6332, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
2015-10-13
Published