Lucene search

K
kasperskyKaspersky LabKLA10490
HistoryMar 20, 2015 - 12:00 a.m.

KLA10490 Denial of service vulnerability in Cisco IOS

2015-03-2000:00:00
Kaspersky Lab
threats.kaspersky.com
15

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.002

Percentile

55.9%

An unspecified vulnerability was found in Cisco IOS. By exploiting this vulnerability malicious users can modify settings or cause denial of service. This vulnerability can be exploited remotely via a specially designed AN messages.

Original advisories

Cisco alert

Related products

Cisco-IOS

CVE list

CVE-2015-0669 high

Solution

Update to latest version!

Impacts

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • WLF

Write Local Files. Exploitation of vulnerabilities with this impact can lead to writing into some inaccessible files. Files that can be read depends on concrete program errors.

Affected Products

  • Cisco IOS versions 15.4S and 15.4(3)S

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.002

Percentile

55.9%