CVE-2015-4277: Medium severity cisco nx-os vulnerability
The global-configuration implementation on Cisco ASR 9000 devices with software 5.1.3 and 5.3.0 improperly closes vty sessions after a commit/end operation, which allows local users to cause a denial of service (tmp/config file creation, memory consumption, and device hang) via unspecified vectors, aka Bug ID CSCut93842.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4277?
CVE-2015-4277 has a high severity rating as it can lead to a denial of service condition on affected Cisco ASR 9000 devices.
How do I fix CVE-2015-4277?
To fix CVE-2015-4277, update the affected Cisco ASR 9000 devices to the recommended software versions beyond 5.3.0.
What devices are affected by CVE-2015-4277?
CVE-2015-4277 affects Cisco ASR 9000 devices running software versions 5.1.3 and 5.3.0.
What types of attacks can exploit CVE-2015-4277?
Local users can exploit CVE-2015-4277 through unspecified vectors that cause tmp/*config file creation and memory consumption.
What is the impact of CVE-2015-4277 on my network?
The impact of CVE-2015-4277 includes potential device hang and overall network stability issues due to denial of service.