CVE-2015-4201: Input Validation
The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header, aka Bug ID CSCut68058.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4201?
CVE-2015-4201 has a medium severity level due to its potential to cause a denial of service.
How do I fix CVE-2015-4201?
To mitigate CVE-2015-4201, update the Cisco ASR 5000 series software to a version that is not affected by this vulnerability.
What impact does CVE-2015-4201 have on my system?
CVE-2015-4201 can lead to a denial of service, causing the Session Manager to restart unexpectedly.
Which versions of Cisco ASR 5000 are affected by CVE-2015-4201?
CVE-2015-4201 affects Cisco ASR 5000 devices running software versions 17.2.0.59184 and 18.0.L0.59219.
Is CVE-2015-4201 exploitable remotely?
Yes, CVE-2015-4201 can be exploited remotely by sending an invalid TCP/IP header to the vulnerable device.