First published: Mon Aug 31 2015(Updated: )
Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted SIP packet, aka Bug IDs CSCta74749 and CSCta77008.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =2.1.0 | |
Cisco IOS XE Software | =2.1.1 | |
Cisco IOS XE Software | =2.1.2 | |
Cisco IOS XE Software | =2.1.3 | |
Cisco IOS XE Software | =2.2.1 | |
Cisco IOS XE Software | =2.2.2 | |
Cisco IOS XE Software | =2.2.3 | |
Cisco IOS XE Software | =2.3.0 | |
Cisco IOS XE Software | =2.3.0t | |
Cisco IOS XE Software | =2.3.1t | |
Cisco IOS XE Software | =2.3.2 | |
Cisco IOS XE Software | =2.4.0 | |
Cisco IOS XE Software | =2.4.1 | |
Cisco IOS XE Software | =2.4.2 | |
Cisco IOS XE Software | =2.4.3 | |
Cisco IOS XE Software | =2.5.0 | |
Cisco ASR 1001 | ||
Cisco ASR 1001-X | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6271 has a high severity rating as it allows remote attackers to cause a denial of service.
To mitigate CVE-2015-6271, upgrade to a non-vulnerable version of Cisco IOS XE that is higher than 2.5.0.
Cisco IOS XE versions from 2.1.0 to 2.4.3 and 2.5.0 on ASR 1000 devices are affected by CVE-2015-6271.
CVE-2015-6271 is exploited via crafted SIP packets aimed at causing an Embedded Services Processor crash.
There is no specific workaround for CVE-2015-6271; updating to a secure version is the recommended action.