5

CVE-2015-4293

The packet-reassembly implementation in Cisco IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (CPU consumption or packet loss) via fragmented (1) IPv4 or (2) IPv6 packets that trigger ATTN-3-SYNC_TIMEOUT errors after reassembly failures, aka Bug ID CSCuo37957.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version2.1.0
CiscoIos Xe Version2.1.1
CiscoIos Xe Version2.1.2
CiscoIos Xe Version2.2.1
CiscoIos Xe Version2.2.2
CiscoIos Xe Version2.2.3
CiscoIos Xe Version2.3.0
CiscoIos Xe Version2.3.0t
CiscoIos Xe Version2.3.1t
CiscoIos Xe Version2.3.2
CiscoIos Xe Version2.4.0
CiscoIos Xe Version2.4.1
CiscoIos Xe Version2.5.0
CiscoIos Xe Version2.5.1
CiscoIos Xe Version2.5.2
CiscoIos Xe Version2.6.0
CiscoIos Xe Version2.6.1
CiscoIos Xe Version2.6.2
CiscoIos Xe Version3.10s.0
CiscoIos Xe Version3.10s.0a
CiscoIos Xe Version3.10s.1
CiscoIos Xe Version3.10s.2
CiscoIos Xe Version3.10s.3
CiscoIos Xe Version3.11s.0
CiscoIos Xe Version3.11s.1
CiscoIos Xe Version3.11s.2
CiscoIos Xe Version3.12s.0
CiscoIos Xe Version3.12s.1
CiscoIos Xe Version3.13s.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.47% 0.637
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P