CVE-2015-6282
Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers to cause a denial of service (device reload) via IPv4 packets that require NAT and MPLS actions, aka Bug…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers to cause a denial of service (device reload) via IPv4 packets that require NAT and MPLS actions, aka Bug ID CSCut96933.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 2.19% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-399
- Affected
- cisco/ios xe
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150923-iosxeVendor Advisory
- http://www.securitytracker.com/id/1033645Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150923-iosxeVendor Advisory
- http://www.securitytracker.com/id/1033645Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.