CVE-2015-6359
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote attackers to cause a denial of service (memory consumption or device crash) via a flood of…
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote attackers to cause a denial of service (memory consumption or device crash) via a flood of crafted ND messages, aka Bug ID CSCup28217.
- CVSS 2.0
- 6.1 MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- cisco/ios
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151214-iosVendor Advisory
- http://www.securityfocus.com/bid/79200
- http://www.securitytracker.com/id/1034432
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151214-iosVendor Advisory
- http://www.securityfocus.com/bid/79200
- http://www.securitytracker.com/id/1034432
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.