First published: Fri Apr 03 2015(Updated: )
The SNMP implementation in Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices, when single-switch Virtual Switching System (VSS) is configured, allows remote authenticated users to cause a denial of service (device crash) by performing SNMP polling, aka Bug ID CSCuq04574.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Cisco IOS | =15.1\(2\)sg4 | |
Puppet Cisco IOS | =15.1sg | |
Cisco Catalyst 4503-e | ||
Cisco Catalyst 4503 | ||
Cisco Catalyst 4506-E | ||
Cisco Catalyst 4507R+E | ||
Cisco Catalyst 4507R/E | ||
Cisco Catalyst 4510R+E | ||
Cisco Catalyst 4510R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0687 has a severity rating that can lead to denial of service due to device crashes.
To fix CVE-2015-0687, upgrade to a newer version of Cisco IOS that is not affected by this vulnerability.
CVE-2015-0687 affects remote authenticated users of Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices with single-switch VSS configuration.
The impact of CVE-2015-0687 includes the potential for remote authenticated users to crash the device via SNMP polling.
Devices running Cisco IOS 15.1(2)SG4 or 15.1sg configurations on Catalyst 4500 are potentially vulnerable to CVE-2015-0687.