First published: Wed Apr 29 2015(Updated: )
Cisco IOS 15.4S, 15.4SN, and 15.5S and IOS XE 3.13S and 3.14S allow remote attackers to cause a denial of service (device crash) by including an IA_NA option in a DHCPv6 Solicit message on the local network, aka Bug ID CSCur29956.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE | =3.13s.0 | |
Cisco IOS XE | =3.13s.1 | |
Cisco IOS XE | =3.14s.0 | |
Cisco IOS | =15.4\(3\)s | |
Cisco IOS | =15.4\(3\)s1 | |
Cisco IOS | =15.4\(3\)sn1 | |
Cisco IOS | =15.4s | |
Cisco IOS | =15.4sn | |
Cisco IOS | =15.5\(1\)s | |
Cisco IOS | =15.5s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0708 has a severity rating that indicates it can lead to a denial of service due to device crashes.
To fix CVE-2015-0708, upgrade to a version of Cisco IOS or IOS XE that is not affected by this vulnerability.
CVE-2015-0708 affects Cisco IOS version 15.4S, 15.5S, and IOS XE versions 3.13S and 3.14S.
CVE-2015-0708 enables remote attackers to cause a denial of service by sending specially crafted DHCPv6 messages.
Yes, CVE-2015-0708 can be exploited remotely by sending a malformed DHCPv6 Solicit message on the local network.