7.8

CVE-2015-4291

Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version2.1.0
CiscoIos Xe Version2.1.1
CiscoIos Xe Version2.1.2
CiscoIos Xe Version2.2.1
CiscoIos Xe Version2.2.2
CiscoIos Xe Version2.2.3
CiscoIos Xe Version2.3.0
CiscoIos Xe Version2.3.0t
CiscoIos Xe Version2.3.1t
CiscoIos Xe Version2.3.2
CiscoIos Xe Version2.4.0
CiscoIos Xe Version2.4.1
CiscoIos Xe Version2.5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.43% 0.615
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C