First published: Wed Sep 02 2015(Updated: )
The IPv4 implementation on Cisco ASR 1000 devices with software 15.5(3)S allows remote attackers to cause a denial of service (ESP QFP CPU consumption) by triggering packet fragmentation and reassembly, aka Bug ID CSCuv71273.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco ASR 1000 Series Software | =15.5\(3\)s | |
Cisco ASR 1000 Series |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6274 has a medium severity level due to its potential to cause a denial of service.
To fix CVE-2015-6274, you should upgrade the Cisco ASR 1000 Series software to a version later than 15.5(3)S.
CVE-2015-6274 affects Cisco ASR 1000 devices running software version 15.5(3)S.
CVE-2015-6274 allows remote attackers to cause a denial of service by exploiting packet fragmentation and reassembly.
There are no documented workarounds for CVE-2015-6274, so upgrading the software is the recommended course of action.