First published: Fri Sep 25 2015(Updated: )
Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers to cause a denial of service (device reload) via IPv4 packets that require NAT and MPLS actions, aka Bug ID CSCut96933.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Web UI | =2.1.0 | |
Cisco IOS XE Web UI | =2.1.1 | |
Cisco IOS XE Web UI | =2.1.2 | |
Cisco IOS XE Web UI | =2.1.3 | |
Cisco IOS XE Web UI | =2.2.1 | |
Cisco IOS XE Web UI | =2.2.2 | |
Cisco IOS XE Web UI | =2.2.3 | |
Cisco IOS XE Web UI | =2.3.0 | |
Cisco IOS XE Web UI | =2.3.0t | |
Cisco IOS XE Web UI | =2.3.1t | |
Cisco IOS XE Web UI | =2.3.2 | |
Cisco IOS XE Web UI | =2.4.0 | |
Cisco IOS XE Web UI | =2.4.1 | |
Cisco IOS XE Web UI | =2.4.2 | |
Cisco IOS XE Web UI | =2.4.3 | |
Cisco IOS XE Web UI | =2.5.0 | |
Cisco IOS XE Web UI | =2.5.1 | |
Cisco IOS XE Web UI | =2.5.2 | |
Cisco IOS XE Web UI | =2.6.0 | |
Cisco IOS XE Web UI | =2.6.1 | |
Cisco IOS XE Web UI | =2.6.2 | |
Cisco IOS XE Web UI | =2.6.2a | |
Cisco IOS XE Web UI | =3.1s.0 | |
Cisco IOS XE Web UI | =3.1s.1 | |
Cisco IOS XE Web UI | =3.1s.2 | |
Cisco IOS XE Web UI | =3.1s.3 | |
Cisco IOS XE Web UI | =3.1s.4 | |
Cisco IOS XE Web UI | =3.1s.4a | |
Cisco IOS XE Web UI | =3.1s.5 | |
Cisco IOS XE Web UI | =3.1s.6 | |
Cisco IOS XE Web UI | =3.2s.0 | |
Cisco IOS XE Web UI | =3.2s.1 | |
Cisco IOS XE Web UI | =3.2s.2 | |
Cisco IOS XE Web UI | =3.2s.3 | |
Cisco IOS XE Web UI | =3.3s.0 | |
Cisco IOS XE Web UI | =3.3s.1 | |
Cisco IOS XE Web UI | =3.3s.2 | |
Cisco IOS XE Web UI | =3.4s.0 | |
Cisco IOS XE Web UI | =3.4s.0a | |
Cisco IOS XE Web UI | =3.4s.1 | |
Cisco IOS XE Web UI | =3.4s.2 | |
Cisco IOS XE Web UI | =3.4s.3 | |
Cisco IOS XE Web UI | =3.4s.4 | |
Cisco IOS XE Web UI | =3.4s.5 | |
Cisco IOS XE Web UI | =3.4s.6 | |
Cisco IOS XE Web UI | =3.5s.0 | |
Cisco IOS XE Web UI | =3.5s.1 | |
Cisco IOS XE Web UI | =3.5s.2 | |
Cisco IOS XE Web UI | =3.5s_base | |
Cisco IOS XE Web UI | =3.6s.0 | |
Cisco IOS XE Web UI | =3.6s.1 | |
Cisco IOS XE Web UI | =3.6s.2 | |
Cisco IOS XE Web UI | =3.6s_base | |
Cisco IOS XE Web UI | =3.7s.0 | |
Cisco IOS XE Web UI | =3.7s.1 | |
Cisco IOS XE Web UI | =3.7s.2 | |
Cisco IOS XE Web UI | =3.7s.3 | |
Cisco IOS XE Web UI | =3.7s.4 | |
Cisco IOS XE Web UI | =3.7s.5 | |
Cisco IOS XE Web UI | =3.7s.6 | |
Cisco IOS XE Web UI | =3.7s.7 | |
Cisco IOS XE Web UI | =3.7s_base | |
Cisco IOS XE Web UI | =3.8s.0 | |
Cisco IOS XE Web UI | =3.8s.1 | |
Cisco IOS XE Web UI | =3.8s.2 | |
Cisco IOS XE Web UI | =3.8s_base | |
Cisco IOS XE Web UI | =3.9s.0 | |
Cisco IOS XE Web UI | =3.9s.1 | |
Cisco IOS XE Web UI | =3.9s.2 | |
Cisco IOS XE Web UI | =3.10s.0 | |
Cisco IOS XE Web UI | =3.10s.0a | |
Cisco IOS XE Web UI | =3.10s.01 | |
Cisco IOS XE Web UI | =3.10s.1 | |
Cisco IOS XE Web UI | =3.10s.2 | |
Cisco IOS XE Web UI | =3.10s.3 | |
Cisco IOS XE Web UI | =3.10s.4 | |
Cisco IOS XE Web UI | =3.10s.5 | |
Cisco IOS XE Web UI | =3.11s.0 | |
Cisco IOS XE Web UI | =3.11s.1 | |
Cisco IOS XE Web UI | =3.11s.2 | |
Cisco IOS XE Web UI | =3.11s.3 | |
Cisco IOS XE Web UI | =3.11s.4 | |
Cisco IOS XE Web UI | =3.12s.0 | |
Cisco IOS XE Web UI | =3.12s.1 | |
Cisco IOS XE Web UI | =3.12s.2 | |
Cisco IOS XE Web UI | =3.12s.3 | |
Cisco IOS XE Web UI | =3.13s.0 | |
Cisco IOS XE Web UI | =3.13s.1 | |
Cisco IOS XE Web UI | =3.13s.2 | |
Cisco IOS XE Web UI | =3.14s.0 | |
Cisco IOS XE Web UI | =3.14s.1 | |
Cisco IOS XE Web UI | =3.14s.2 | |
Cisco IOS XE Web UI | =3.14s.3 | |
Cisco IOS XE Web UI | =3.14s.4 | |
Cisco IOS XE Web UI | =3.15s.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6282 has a high severity rating due to the potential for remote attackers to cause denial of service through device reloads.
To fix CVE-2015-6282, you should upgrade to one of the patched versions of Cisco IOS XE as specified in the security advisory.
CVE-2015-6282 affects Cisco IOS XE devices configured to require Network Address Translation (NAT) and Multiprotocol Label Switching (MPLS) actions.
CVE-2015-6282 affects Cisco IOS XE versions prior to 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S.
The attack vector for CVE-2015-6282 is through specially crafted IPv4 packets that trigger the flaw in affected Cisco IOS XE systems.