CVE-2015-6429
published 2015-12-19CVE-2015-6429: The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.74%
75.1th percentile
The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka Bug ID CSCuw08236.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_and_ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS and IOS XE Software IKEv1 State Machine Denial of Service Vulnerability
vendor_cisco·2015-12-18·CVSS 5.0
CVE-2015-6429 [MEDIUM] CWE-119 Cisco IOS and IOS XE Software IKEv1 State Machine Denial of Service Vulnerability
Cisco IOS and IOS XE Software IKEv1 State Machine Denial of Service Vulnerability
A vulnerability in the Internet Key Exchange (IKEv1) state machine of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to tear down valid IPsec connections, resulting in a partial denial of service (DoS) condition.
The vulnerability is due to insufficient condition checks in the IKEv1 state machine. An attacker could exploit this vulnerability by sending a spoofed, specific IKEv1 packet to an endpoint of an IPsec tunnel. A successful exploit could allow the attacker to tear down IPsec tunnels that terminate on the endpoint, causing a partial DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vuln
Cisco
Cisco IOS and IOS XE Software IKEv1 State Machine Denial of Service Vulnerability
vendor_cisco
CVE-2015-6429 Cisco IOS and IOS XE Software IKEv1 State Machine Denial of Service Vulnerability
CVE-2015-6429: Cisco IOS and IOS XE Software IKEv1 State Machine Denial of Service Vulnerability
A vulnerability in the Internet Key Exchange (IKEv1) state machine of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to tear down valid IPsec connections, resulting in a partial denial of service (DoS) condition. The vulnerability is due to insufficient condition checks in the IKEv1 state machine. An attacker could exploit this vulnerability by sending a spoofed, specific IKEv1 packet to an endpoint of an IPsec tunnel. A successful exploit could allow the attacker to tear down IPsec tunnels that terminate on the endpoint, causing a partial DoS condition. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-119, CWE-119
B
GHSA
GHSA-rv2q-3w65-6h82: The IKEv1 state machine in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-6429 [MEDIUM] GHSA-rv2q-3w65-6h82: The IKEv1 state machine in Cisco IOS 15
The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka Bug ID CSCuw08236.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-12-19
Published