PT-2015-1979 · Cisco · Asr 1000+2
Published
2015-08-31
·
Updated
2017-09-20
·
CVE-2015-6269
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE versions prior to 2.2.3 on ASR 1000 devices
Description
The issue is related to resource management errors in the Cisco IOS operating system. It allows remote attackers to cause a denial of service, specifically an Embedded Services Processor crash, by sending crafted IPv4 or IPv6 packets.
Recommendations
For Cisco IOS XE versions prior to 2.2.3 on ASR 1000 devices, update to version 2.2.3 or later to resolve the issue. As a temporary workaround, consider implementing packet filtering to restrict the reception of specially crafted IPv4 or IPv6 packets.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asr 1000
Cisco Ios
Cisco Ios Xe