CVE-2015-6272: High severity cisco ios xe software vulnerability
Cisco IOS XE 2.1.0 through 2.2.3 and 2.3.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted H.323 packet, aka Bug ID CSCsx35393, CSCsx07094, and CSCsw93064.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6272?
CVE-2015-6272 is classified with a moderate severity rating due to its potential to cause a denial of service.
How do I fix CVE-2015-6272?
To remediate CVE-2015-6272, upgrade to Cisco IOS XE version 2.3.1 or later.
What devices are affected by CVE-2015-6272?
CVE-2015-6272 affects Cisco ASR 1000 devices running IOS XE versions 2.1.0 through 2.2.3 and 2.3.0.
What type of attack does CVE-2015-6272 facilitate?
CVE-2015-6272 allows remote attackers to cause a denial of service by sending a crafted H.323 packet.
Is there a workaround for CVE-2015-6272?
There are no specific workarounds recommended for CVE-2015-6272, and updating the software is the primary mitigation.