CVE-2015-0646: High severity Cisco IOS XE vulnerability
Memory leak in the TCP input module in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.3.xXO, 3.5.xE, 3.6.xE, 3.8.xS through 3.10.xS before 3.10.5S, and 3.11.xS and 3.12.xS before 3.12.3S allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted TCP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCum94811.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0646?
CVE-2015-0646 has a high severity rating because it allows remote attackers to cause memory consumption or device reload, leading to a denial of service.
How do I fix CVE-2015-0646?
To fix CVE-2015-0646, upgrade to Cisco IOS or IOS XE versions that are patched against this vulnerability.
Which Cisco products are affected by CVE-2015-0646?
CVE-2015-0646 affects multiple versions of Cisco IOS 12.2, 12.4, and 15.x, as well as Cisco IOS XE versions before 3.12.3S.
What type of vulnerability is CVE-2015-0646?
CVE-2015-0646 is a denial of service vulnerability caused by a memory leak in the TCP input module.
Can CVE-2015-0646 be exploited remotely?
Yes, CVE-2015-0646 can be exploited remotely, making it particularly critical for network security.