First published: Sat Aug 29 2015(Updated: )
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv4 UDP packet, aka Bug ID CSCsw95482.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =2.2.1 | |
Cisco IOS XE Software | =2.2.2 | |
Cisco ASR 1001 | ||
Cisco ASR 1001-X | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6268 has a severity rating that indicates a denial of service vulnerability allowing remote attackers to crash the Embedded Services Processor.
To fix CVE-2015-6268, update to Cisco IOS XE version 2.2.3 or later.
CVE-2015-6268 affects Cisco ASR 1000 devices running IOS XE versions prior to 2.2.3.
CVE-2015-6268 can be exploited via crafted IPv4 UDP packets that trigger a denial of service.
There are no known workarounds for CVE-2015-6268; the only solution is to apply the relevant software update.