CVE-2015-0672: Medium severity Cisco IOS XR vulnerability
Published Mar 26, 2015
·Updated
The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denial of service (service outage) via a flood of crafted DHCP packets, aka Bug ID CSCup67822.
Affected Software
7 affected components
Cisco IOS XR=5.2.2
Cisco Asr 9001
Cisco Asr 9006
Cisco Asr 9010
Cisco Asr 9904
Cisco Asr 9912
Cisco Asr 9922
Event History
Mar 26, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0672?
CVE-2015-0672 has a medium severity rating, posing a risk of denial of service.
2
How do I fix CVE-2015-0672?
To fix CVE-2015-0672, upgrade the Cisco IOS XR to a version later than 5.2.2.
3
Who is affected by CVE-2015-0672?
CVE-2015-0672 affects devices running Cisco IOS XR version 5.2.2 on ASR 9000 routers.
4
What type of attack does CVE-2015-0672 involve?
CVE-2015-0672 involves a denial of service attack through a flood of crafted DHCP packets.
5
Is CVE-2015-0672 a remote vulnerability?
Yes, CVE-2015-0672 can be exploited remotely by attackers.