CVE-2015-6267: High severity cisco ios xe software vulnerability
Published Aug 29, 2015
·Updated
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted L2TP packet, aka Bug IDs CSCsw95722 and CSCsw95496.
Affected Software
9 affected components
Cisco IOS XE=2.2.1
Cisco IOS XE=2.2.2
Cisco Asr 1001
Cisco Asr 1001-x
Cisco Asr 1002
Cisco Asr 1002-x
Cisco Asr 1004
Cisco Asr 1006
Cisco Asr 1013
Event History
Aug 29, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6267?
CVE-2015-6267 has a severity rating that could lead to a denial of service on vulnerable Cisco IOS XE devices.
2
How do I fix CVE-2015-6267?
To mitigate CVE-2015-6267, you should upgrade Cisco IOS XE to version 2.2.3 or later.
3
Which devices are affected by CVE-2015-6267?
CVE-2015-6267 affects Cisco IOS XE versions 2.2.1 and 2.2.2 running on ASR 1000 series devices.
4
What type of attack does CVE-2015-6267 enable?
CVE-2015-6267 can be exploited by remote attackers to cause the Embedded Services Processor to crash.
5
Is CVE-2015-6267 a remote vulnerability?
Yes, CVE-2015-6267 is a remote vulnerability that can be triggered through specially crafted L2TP packets.