First published: Tue Jun 23 2015(Updated: )
Race condition in Cisco IOS 12.2SCH in the Performance Routing Engine (PRE) module on uBR10000 devices, when NetFlow and an MPLS IPv6 VPN are configured, allows remote attackers to cause a denial of service (PXF process crash) by sending malformed MPLS 6VPE packets quickly, aka Bug ID CSCud83396.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Cisco IOS | =12.2\(33\)sch | |
Puppet Cisco IOS | =12.2sch | |
Cisco uBR10000 Cable Modem Termination System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4203 has a CVSS score indicating a high severity vulnerability that can lead to a denial of service.
To fix CVE-2015-4203, upgrade to a non-vulnerable version of Cisco IOS that addresses the race condition.
CVE-2015-4203 specifically affects Cisco IOS 12.2SCH on uBR10000 devices when certain configurations are in use.
CVE-2015-4203 is associated with a denial-of-service attack made possible by sending malformed MPLS 6VPE packets.
Currently, there are no documented workarounds for CVE-2015-4203 except to apply the relevant software updates.