CVE-2015-6334: Input Validation
Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045 allow remote attackers to cause a denial of service (vpnmgr process restart) via a crafted header in a TACACS packet, aka Bug ID CSCuw01984.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6334?
CVE-2015-6334 has been classified with a severity rating that indicates it can lead to a denial of service attack on affected Cisco ASR 5000 and 5500 devices.
How do I fix CVE-2015-6334?
To mitigate CVE-2015-6334, it is recommended to upgrade your Cisco ASR 5000 and 5500 devices to the latest software versions that are not vulnerable.
What causes CVE-2015-6334?
CVE-2015-6334 is caused by a vulnerability that allows remote attackers to trigger a restart of the vpnmgr process through a crafted TACACS header.
Which devices are affected by CVE-2015-6334?
CVE-2015-6334 affects Cisco ASR 5000 and 5500 devices running software versions 18.0.0.57828 and 19.0.M0.61045.
Can CVE-2015-6334 be exploited remotely?
Yes, CVE-2015-6334 can be exploited remotely by attackers sending specially crafted TACACS packets.