CVE-2015-6268: High severity cisco ios xe software vulnerability
Published Aug 29, 2015
·Updated
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv4 UDP packet, aka Bug ID CSCsw95482.
Affected Software
9 affected components
Cisco IOS XE=2.2.1
Cisco IOS XE=2.2.2
Cisco Asr 1001
Cisco Asr 1001-x
Cisco Asr 1002
Cisco Asr 1002-x
Cisco Asr 1004
Cisco Asr 1006
Cisco Asr 1013
Event History
Aug 29, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6268?
CVE-2015-6268 has a severity rating that indicates a denial of service vulnerability allowing remote attackers to crash the Embedded Services Processor.
2
How do I fix CVE-2015-6268?
To fix CVE-2015-6268, update to Cisco IOS XE version 2.2.3 or later.
3
What devices are affected by CVE-2015-6268?
CVE-2015-6268 affects Cisco ASR 1000 devices running IOS XE versions prior to 2.2.3.
4
What kind of attack can exploit CVE-2015-6268?
CVE-2015-6268 can be exploited via crafted IPv4 UDP packets that trigger a denial of service.
5
Is there a workaround for CVE-2015-6268?
There are no known workarounds for CVE-2015-6268; the only solution is to apply the relevant software update.