CVE-2015-6274: Buffer Overflow
Published Sep 2, 2015
·Updated
The IPv4 implementation on Cisco ASR 1000 devices with software 15.5(3)S allows remote attackers to cause a denial of service (ESP QFP CPU consumption) by triggering packet fragmentation and reassembly, aka Bug ID CSCuv71273.
Affected Software
2 affected components
Cisco Asr 1000 Series Software=15.5\(3\)s
Cisco ASR 1000
Event History
Sep 2, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6274?
CVE-2015-6274 has a medium severity level due to its potential to cause a denial of service.
2
How do I fix CVE-2015-6274?
To fix CVE-2015-6274, you should upgrade the Cisco ASR 1000 Series software to a version later than 15.5(3)S.
3
What devices are affected by CVE-2015-6274?
CVE-2015-6274 affects Cisco ASR 1000 devices running software version 15.5(3)S.
4
What type of attack does CVE-2015-6274 enable?
CVE-2015-6274 allows remote attackers to cause a denial of service by exploiting packet fragmentation and reassembly.
5
Is there a known workaround for CVE-2015-6274?
There are no documented workarounds for CVE-2015-6274, so upgrading the software is the recommended course of action.