Vulnerability Name: | CVE-2015-4285 (CCN-104948) | ||||||||
Assigned: | 2015-07-22 | ||||||||
Published: | 2015-07-22 | ||||||||
Updated: | 2015-09-03 | ||||||||
Summary: | The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports continuously, aka Bug ID CSCur88273. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-399 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-4285 Source: CCN Type: Cisco Vulnerability Alert 40068 Cisco IOS XR LPTS Network Stack Remote Denial of Service Vulnerability Source: CISCO Type: Vendor Advisory 20150722 Cisco IOS XR LPTS Network Stack Remote Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1033043 Source: XF Type: UNKNOWN ciscoiosxr-cve20154285-dos(104948) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |