First published: Mon Aug 31 2015(Updated: )
Cisco IOS XE 2.1.0 through 2.2.3 and 2.3.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted H.323 packet, aka Bug ID CSCsx35393, CSCsx07094, and CSCsw93064.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =2.1.0 | |
Cisco IOS XE Software | =2.1.1 | |
Cisco IOS XE Software | =2.1.2 | |
Cisco IOS XE Software | =2.1.3 | |
Cisco IOS XE Software | =2.2.1 | |
Cisco IOS XE Software | =2.2.2 | |
Cisco IOS XE Software | =2.2.3 | |
Cisco IOS XE Software | =2.3.0 | |
Cisco ASR 1001 | ||
Cisco ASR 1001-X | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6272 is classified with a moderate severity rating due to its potential to cause a denial of service.
To remediate CVE-2015-6272, upgrade to Cisco IOS XE version 2.3.1 or later.
CVE-2015-6272 affects Cisco ASR 1000 devices running IOS XE versions 2.1.0 through 2.2.3 and 2.3.0.
CVE-2015-6272 allows remote attackers to cause a denial of service by sending a crafted H.323 packet.
There are no specific workarounds recommended for CVE-2015-6272, and updating the software is the primary mitigation.