PT-2015-6450 · Cisco · Cisco Ios Xr
Published
2015-06-17
·
Updated
2016-12-28
·
CVE-2015-4191
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR version 5.2.1
Description
A vulnerability in IP version 6 (IPv6) processing could allow an unauthenticated, remote attacker to cause a reload of the ipv6 io service. The issue is due to improper processing of a malformed IPv6 packet by a device configured to process such packets. An attacker could exploit this by sending a malformed IPv6 packet to a device configured for IPv6. To exploit this, an attacker may need additional information about the targeted device, such as its IPv6 configuration.
Recommendations
For Cisco IOS XR version 5.2.1, update to a newer version that includes the fix for this issue, as confirmed by Cisco. As a temporary workaround, consider restricting access to IPv6 packets or disabling IPv6 processing on the device until a patch is applied.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xr