CVE-2015-0654: Race Condition
Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, aka Bug ID CSCuq40652.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0654?
CVE-2015-0654 has a moderate severity level due to its ability to cause a denial of service.
How do I fix CVE-2015-0654?
To fix CVE-2015-0654, upgrade to Cisco Intrusion Prevention System Software version 7.3(3)E4 or later.
What type of attack does CVE-2015-0654 facilitate?
CVE-2015-0654 facilitates a denial of service attack by allowing remote attackers to hang the process through multiple HTTPS session establishment.
Which Cisco Intrusion Prevention System versions are affected by CVE-2015-0654?
CVE-2015-0654 affects Cisco Intrusion Prevention System Software versions 7.2(1)E4, 7.2(2)E4, and 7.3(2)E4.
What is the impact of CVE-2015-0654 on systems?
The impact of CVE-2015-0654 is that it can lead to outages or service interruptions due to process hangs.