CVE-2015-6367
published 2015-11-14CVE-2015-6367: Cisco Aironet 1800 devices with software 8.1(131.0) allow remote attackers to cause a denial of service (CPU consumption) by improperly establishing many SSHv2…
PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.91%
77.5th percentile
Cisco Aironet 1800 devices with software 8.1(131.0) allow remote attackers to cause a denial of service (CPU consumption) by improperly establishing many SSHv2 connections, aka Bug ID CSCux13374.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | aironet_1800_series_access_point_sshv2 | — | — |
| cisco | aironet_access_point_software | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f4p3-cpxc-wqh2: Cisco Aironet 1800 devices with software 8
ghsa_unreviewed·2022-05-17
CVE-2015-6367 [HIGH] GHSA-f4p3-cpxc-wqh2: Cisco Aironet 1800 devices with software 8
Cisco Aironet 1800 devices with software 8.1(131.0) allow remote attackers to cause a denial of service (CPU consumption) by improperly establishing many SSHv2 connections, aka Bug ID CSCux13374.
Cisco
Cisco Aironet 1800 Series Access Point SSHv2 Denial of Service Vulnerability
vendor_cisco·2015-11-13·CVSS 5.0
CVE-2015-6367 [MEDIUM] CWE-399 Cisco Aironet 1800 Series Access Point SSHv2 Denial of Service Vulnerability
Cisco Aironet 1800 Series Access Point SSHv2 Denial of Service Vulnerability
A vulnerability in the Secure Shell Version 2 (SSHv2) protocol of Cisco Aironet 1800 Series Access Points could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization and an accumulation of SSHv2 connections.
The vulnerability is due to improper handling of incoming SSHv2 connections that do not complete properly. An attacker could exploit this vulnerability by sending a high number of crafted SSHv2 connections to an affected device. An exploit could allow the attacker to cause a DoS condition due to high CPU utilization and an accumulation of SSHv2 connections.
Cisco has not released software updates that address this vulnerability. Workarounds that m
Cisco
Cisco Aironet 1800 Series Access Point SSHv2 Denial of Service Vulnerability
vendor_cisco
CVE-2015-6367 Cisco Aironet 1800 Series Access Point SSHv2 Denial of Service Vulnerability
CVE-2015-6367: Cisco Aironet 1800 Series Access Point SSHv2 Denial of Service Vulnerability
A vulnerability in the Secure Shell Version 2 (SSHv2) protocol of Cisco Aironet 1800 Series Access Points could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization and an accumulation of SSHv2 connections. The vulnerability is due to improper handling of incoming SSHv2 connections that do not complete properly. An attacker could exploit this vulnerability by sending a high number of crafted SSHv2 connections to an affected device. An exploit could allow the attacker to cause a DoS condition due to high CPU utilization and an accumulation of SSHv2 connections. Cisco has not released software updates that address this vulnerability.
CWE: C
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-14
Published