First published: Mon Feb 16 2015(Updated: )
Race condition in the Common Classification Engine (CCE) in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCuj96752.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | <=15.4\(2\)t3 | |
Cisco IOS | =15.4\(1\)t | |
Cisco IOS | =15.4\(1\)t1 | |
Cisco IOS | =15.4\(1\)t2 | |
Cisco IOS | =15.4\(1\)t3 | |
Cisco IOS | =15.4\(1\)t4 | |
Cisco IOS | =15.4\(2\)t | |
Cisco IOS | =15.4\(2\)t1 | |
Cisco IOS | =15.4\(2\)t2 | |
Cisco IOS | =15.4t |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0609 is classified as a high-severity vulnerability that can lead to a denial of service condition.
To address CVE-2015-0609, upgrade your Cisco IOS to a version later than 15.4(2)T3.
The affected versions include all Cisco IOS versions up to and including 15.4(2)T3, as well as 15.4(1)t and its subsequent releases.
CVE-2015-0609 allows remote attackers to exploit a race condition that can cause the device to reload unexpectedly.
There are no specific workarounds recommended for CVE-2015-0609 besides upgrading to a patched version of Cisco IOS.