First published: Thu Jul 30 2015(Updated: )
The packet-reassembly implementation in Cisco IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (CPU consumption or packet loss) via fragmented (1) IPv4 or (2) IPv6 packets that trigger ATTN-3-SYNC_TIMEOUT errors after reassembly failures, aka Bug ID CSCuo37957.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Web UI | =2.1.0 | |
Cisco IOS XE Web UI | =2.1.1 | |
Cisco IOS XE Web UI | =2.1.2 | |
Cisco IOS XE Web UI | =2.2.1 | |
Cisco IOS XE Web UI | =2.2.2 | |
Cisco IOS XE Web UI | =2.2.3 | |
Cisco IOS XE Web UI | =2.3.0 | |
Cisco IOS XE Web UI | =2.3.0t | |
Cisco IOS XE Web UI | =2.3.1t | |
Cisco IOS XE Web UI | =2.3.2 | |
Cisco IOS XE Web UI | =2.4.0 | |
Cisco IOS XE Web UI | =2.4.1 | |
Cisco IOS XE Web UI | =2.5.0 | |
Cisco IOS XE Web UI | =2.5.1 | |
Cisco IOS XE Web UI | =2.5.2 | |
Cisco IOS XE Web UI | =2.6.0 | |
Cisco IOS XE Web UI | =2.6.1 | |
Cisco IOS XE Web UI | =2.6.2 | |
Cisco IOS XE Web UI | =3.10s.0 | |
Cisco IOS XE Web UI | =3.10s.0a | |
Cisco IOS XE Web UI | =3.10s.1 | |
Cisco IOS XE Web UI | =3.10s.2 | |
Cisco IOS XE Web UI | =3.10s.3 | |
Cisco IOS XE Web UI | =3.11s.0 | |
Cisco IOS XE Web UI | =3.11s.1 | |
Cisco IOS XE Web UI | =3.11s.2 | |
Cisco IOS XE Web UI | =3.12s.0 | |
Cisco IOS XE Web UI | =3.12s.1 | |
Cisco IOS XE Web UI | =3.13s.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4293 has a high severity rating due to its potential to cause denial of service.
To fix CVE-2015-4293, it is recommended to upgrade to the latest version of Cisco IOS XE that contains the security patch.
CVE-2015-4293 involves a denial of service attack through the exploitation of fragmented IPv4 and IPv6 packets.
CVE-2015-4293 affects multiple versions of Cisco IOS XE, including versions from 2.1.0 to 3.13S.
The impact of CVE-2015-4293 includes excessive CPU consumption and packet loss leading to service disruptions.