CVE-2015-4201
The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header,…
Does this matter?
Lower severity and a low EPSS score (2.96%). Track it; it rarely justifies an emergency change on its own.
Description
The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header, aka Bug ID CSCut68058.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.96% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/asr 5000 series software
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39431Vendor Advisory
- http://www.securityfocus.com/bid/75323Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032677Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39431Vendor Advisory
- http://www.securityfocus.com/bid/75323Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032677Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.