Lucene search

K
cveCiscoCVE-2015-4199
HistoryJun 27, 2015 - 10:59 a.m.

CVE-2015-4199

2015-06-2710:59:00
CWE-362
cisco
web.nvd.nist.gov
34
cve-2015-4199
cisco
ios
race condition
ipv6
ipv4
denial of service
null pointer free
module crash

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

7

Confidence

High

EPSS

0.002

Percentile

62.2%

Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity with many IPv6 CPE devices, aka Bug ID CSCug47366.

Affected configurations

Nvd
Node
ciscoiosMatch15.3s
VendorProductVersionCPE
ciscoios15.3scpe:2.3:o:cisco:ios:15.3s:*:*:*:*:*:*:*

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

7

Confidence

High

EPSS

0.002

Percentile

62.2%

Related for CVE-2015-4199