First published: Sat Aug 29 2015(Updated: )
Cisco IOS XE before 3.1.2S on ASR 1000 devices mishandles the automatic setup of Virtual Fragment Reassembly (VFR) by certain firewall and NAT components, which allows remote attackers to cause a denial of service (Embedded Services Processor crash) via crafted IP packets, aka Bug IDs CSCtf87624, CSCte93229, CSCtd19103, and CSCti63623.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =2.2.1 | |
Cisco IOS XE Software | =2.2.2 | |
Cisco IOS XE Software | =2.2.3 | |
Cisco IOS XE Software | =3.1.0s | |
Cisco IOS XE Software | =3.1.1s | |
Cisco ASR 1001 | ||
Cisco ASR 1001-X | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6273 has a high severity rating as it can allow remote attackers to cause a denial of service.
To fix CVE-2015-6273, upgrade to Cisco IOS XE versions 3.1.2S or later.
CVE-2015-6273 affects Cisco IOS XE versions 2.2.1, 2.2.2, 2.2.3, and 3.1.0s and 3.1.1s on ASR 1000 devices.
CVE-2015-6273 allows attackers to send crafted IP packets that can crash the Embedded Services Processor.
CVE-2015-6273 involves mishandling in the automatic setup of Virtual Fragment Reassembly by certain firewall and NAT components.