CVE-2015-4275: Medium severity cisco asr 5000 series aggregation services routers vulnerability
Published Jul 16, 2015
·Updated
The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 18.0.0.59167 and 18.0.0.59211 allows remote attackers to cause a denial of service via a malformed header in a GTPv2 packet, aka Bug ID CSCut11534.
Affected Software
2 affected components
Cisco ASR 5000 Series Software=18.0.0.59167
Cisco ASR 5000 Series Software=18.0.0.59211
Event History
Jul 16, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4275?
CVE-2015-4275 has a critical severity level due to its ability to cause a denial of service.
2
How do I fix CVE-2015-4275?
To remediate CVE-2015-4275, upgrade Cisco ASR 5000 to a version later than 18.0.0.59211.
3
Who is affected by CVE-2015-4275?
CVE-2015-4275 affects Cisco ASR 5000 series devices running versions 18.0.0.59167 and 18.0.0.59211.
4
What type of attack does CVE-2015-4275 allow?
CVE-2015-4275 allows remote attackers to launch a denial of service attack using malformed GTPv2 packets.
5
Is CVE-2015-4275 a local or remote vulnerability?
CVE-2015-4275 is a remote vulnerability that can be exploited from outside the affected network.