First published: Wed Jul 08 2015(Updated: )
The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty94202.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =3.5.0s | |
Cisco ASR 1001 | ||
Cisco ASR 1001-X | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4243 is classified as a denial of service vulnerability that could lead to device reload.
To mitigate CVE-2015-4243, ensure that your Cisco IOS XE is updated to a non-vulnerable version.
CVE-2015-4243 specifically affects Cisco IOS XE 3.5.0S running on ASR 1000 devices.
CVE-2015-4243 involves remote attackers sending malformed PPPoE Active Discovery Request packets.
Yes, the vulnerability can potentially be exploited by remote attackers on the local network.