CVE-2015-0610
Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco…
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCun21071.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.43% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- cisco/ios
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0610Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=37423Vendor Advisory
- http://www.securityfocus.com/bid/72565
- http://www.securitytracker.com/id/1031732
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100807
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0610Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=37423Vendor Advisory
- http://www.securityfocus.com/bid/72565
- http://www.securitytracker.com/id/1031732
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100807
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.