CVE-2015-6359
published 2015-12-15CVE-2015-6359: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote…
PriorityP424medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
0.91%
55.6th percentile
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote attackers to cause a denial of service (memory consumption or device crash) via a flood of crafted ND messages, aka Bug ID CSCup28217.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software IPv6 Neighbor Discovery Denial of Service Vulnerability
vendor_cisco·2015-12-14·CVSS 6.1
CVE-2015-6359 [MEDIUM] CWE-119 Cisco IOS XE Software IPv6 Neighbor Discovery Denial of Service Vulnerability
Cisco IOS XE Software IPv6 Neighbor Discovery Denial of Service Vulnerability
A vulnerability in the IPv6 neighbor discovery (ND) handling of Cisco IOS XE Software on ASR platforms could allow an unauthenticated, adjacent attacker to cause an affected device to crash.
The vulnerability is due to insufficient bounds on internal tables. An attacker could exploit this vulnerability by flooding an adjacent IOS XE device with specific ND messages. An exploit could allow the attacker to deplete the available memory, possibly causing an affected device to crash.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/
Cisco
Cisco IOS XE Software IPv6 Neighbor Discovery Denial of Service Vulnerability
vendor_cisco
CVE-2015-6359 Cisco IOS XE Software IPv6 Neighbor Discovery Denial of Service Vulnerability
CVE-2015-6359: Cisco IOS XE Software IPv6 Neighbor Discovery Denial of Service Vulnerability
A vulnerability in the IPv6 neighbor discovery (ND) handling of Cisco IOS XE Software on ASR platforms could allow an unauthenticated, adjacent attacker to cause an affected device to crash. The vulnerability is due to insufficient bounds on internal tables. An attacker could exploit this vulnerability by flooding an adjacent IOS XE device with specific ND messages. An exploit could allow the attacker to deplete the available memory, possibly causing an affected device to crash. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-119, CWE-119
Bug IDs: CSCup28217
GHSA
GHSA-pm63-3g3f-98wc: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-6359 [MEDIUM] CWE-119 GHSA-pm63-3g3f-98wc: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote attackers to cause a denial of service (memory consumption or device crash) via a flood of crafted ND messages, aka Bug ID CSCup28217.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151214-ioshttp://www.securityfocus.com/bid/79200http://www.securitytracker.com/id/1034432http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151214-ioshttp://www.securityfocus.com/bid/79200http://www.securitytracker.com/id/1034432
2015-12-15
Published