CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:A/AC:L/Au:N/C:N/I:N/A:C
EPSS
Percentile
49.6%
Cisco IOS Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on a targeted device.
The vulnerability is due to the processing of IP version 6 (IPv6) packets by the vulnerable version of software on an affected device. If an unauthenticated, remote attacker is able to access and send these packets to the vulnerable device, the device may reload, causing a DoS condition and disrupting normal operations.
Cisco has confirmed this vulnerability in a security advisory and has released updated software.
It is likely that an attacker would need to have access to an internal, private network–more specifically to an adjacent network–to send crafted packets to a vulnerable device. This requirement could limit the possibility for an attack.
In addition, a crafted packet used to exploit this vulnerability would be silently discarded if received on an interface if the packet did not have an MPLS label.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | ios | 12.2se | cpe:2.3:o:cisco:ios:12.2se:*:*:*:*:*:*:* |
cisco | ios | 12.2zi | cpe:2.3:o:cisco:ios:12.2zi:*:*:*:*:*:*:* |
cisco | ios | 15.0m | cpe:2.3:o:cisco:ios:15.0m:*:*:*:*:*:*:* |
cisco | ios | 15.0xa | cpe:2.3:o:cisco:ios:15.0xa:*:*:*:*:*:*:* |
cisco | ios | 15.1t | cpe:2.3:o:cisco:ios:15.1t:*:*:*:*:*:*:* |
cisco | ios | 15.1xb | cpe:2.3:o:cisco:ios:15.1xb:*:*:*:*:*:*:* |
cisco | ios | 12.2sre | cpe:2.3:o:cisco:ios:12.2sre:*:*:*:*:*:*:* |
cisco | ios | 15.0s | cpe:2.3:o:cisco:ios:15.0s:*:*:*:*:*:*:* |
cisco | ios | 15.1s | cpe:2.3:o:cisco:ios:15.1s:*:*:*:*:*:*:* |
cisco | ios | 15.1m | cpe:2.3:o:cisco:ios:15.1m:*:*:*:*:*:*:* |