Vulnerability Name: | CVE-2015-0015 (CCN-98973) | ||||||||
Assigned: | 2014-11-18 | ||||||||
Published: | 2015-01-13 | ||||||||
Updated: | 2019-02-26 | ||||||||
Summary: | Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Network Policy Server (NPS), aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability." | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-399 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-0015 Source: SECUNIA Type: UNKNOWN 62148 Source: CCN Type: Microsoft Security Bulletin MS15-007 Vulnerability in Network Policy Server RADIUS Implementation Could Cause Denial of Service (3014029) Source: CCN Type: Microsoft Security Bulletin MS16-021 Security Update for Network Policy Server RADIUS implementation to Address Denial of Service (3133043) Source: BID Type: UNKNOWN 71933 Source: CCN Type: BID-71933 Microsoft Windows Network Policy Server CVE-2015-0015 Remote Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1031532 Source: MS Type: UNKNOWN MS15-007 Source: XF Type: UNKNOWN ms-nps-cve20150015-dos(98973) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |