CVE-2015-6270: High severity cisco ios xe software vulnerability
Published Aug 31, 2015
·Updated
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv6 packet, aka Bug ID CSCsv98555.
Affected Software
9 affected components
Cisco IOS XE=2.2.1
Cisco IOS XE=2.2.2
Cisco Asr 1001
Cisco Asr 1001-x
Cisco Asr 1002
Cisco Asr 1002-x
Cisco Asr 1004
Cisco Asr 1006
Cisco Asr 1013
Event History
Aug 31, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6270?
CVE-2015-6270 is categorized as a denial of service vulnerability with high severity due to potential impact from remote attackers.
2
How do I fix CVE-2015-6270?
To fix CVE-2015-6270, upgrade Cisco IOS XE software to version 2.2.3 or later on affected ASR 1000 devices.
3
What is the impact of CVE-2015-6270?
The impact of CVE-2015-6270 is a denial of service condition causing an Embedded Services Processor crash.
4
Which devices are affected by CVE-2015-6270?
CVE-2015-6270 affects Cisco ASR 1000 devices running Cisco IOS XE versions 2.2.1 and 2.2.2.
5
Can CVE-2015-6270 be exploited remotely?
Yes, CVE-2015-6270 can be exploited remotely through crafted IPv6 packets.