CVE-2015-6256: Input Validation
Published Aug 22, 2015
·Updated
Cisco ASR 5000 devices with software 19.0.M0.60828 allow remote attackers to cause a denial of service (OSPF process restart) via crafted length fields in headers of OSPF packets, aka Bug ID CSCuv62820.
Affected Software
1 affected component
Cisco ASR 5000 Series Software=19.0.m0.60828
Event History
Aug 22, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6256?
CVE-2015-6256 has a medium severity rating due to the potential for denial of service attacks.
2
How do I fix CVE-2015-6256?
To fix CVE-2015-6256, upgrade the affected Cisco ASR 5000 devices to a later version beyond 19.0.M0.60828.
3
What devices are affected by CVE-2015-6256?
CVE-2015-6256 affects Cisco ASR 5000 devices running software version 19.0.M0.60828.
4
What kind of attack does CVE-2015-6256 enable?
CVE-2015-6256 enables remote attackers to cause a denial of service by restarting the OSPF process.
5
Is CVE-2015-6256 exploitable remotely?
Yes, CVE-2015-6256 is exploitable remotely, allowing attackers to affect the device from anywhere.