First published: Wed Apr 29 2015(Updated: )
The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a series of packets that are considered oversized and trigger improper fragmentation handling, aka Bug IDs CSCup37676 and CSCup30335.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Web UI | =3.10.0s | |
Cisco IOS XE Web UI | =3.10s.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0710 is classified as a high-severity vulnerability that can lead to device reload and denial of service.
To fix CVE-2015-0710, upgrade to Cisco IOS XE versions 3.10.1s or later that address the improper fragmentation handling.
Devices running Cisco IOS XE versions 3.10.0s and 3.10s.01 are vulnerable to CVE-2015-0710.
CVE-2015-0710 exploits improper handling of oversized packets during fragmentation in the Overlay Transport Virtualization (OTV) implementation.
Yes, CVE-2015-0710 allows remote attackers to exploit the vulnerability without authentication to cause a denial of service.