CVE-2015-6432: High severity cisco ios xrv 9000 vulnerability
Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PCEs) for OSPF LSA opaque area updates, which allows remote attackers to cause a denial of service (device reload) via a crafted update, aka Bug ID CSCuw83486.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6432?
CVE-2015-6432 has a high severity rating due to its potential to cause remote denial of service.
How do I fix CVE-2015-6432?
To fix CVE-2015-6432, upgrade your Cisco IOS XR to a version that is not affected by this vulnerability.
What systems are affected by CVE-2015-6432?
CVE-2015-6432 affects Cisco IOS XR versions 4.2.0, 4.3.0, and 5.0.0 through 5.3.2.
What type of attack is possible with CVE-2015-6432?
CVE-2015-6432 allows attackers to perform a denial of service attack resulting in device reloads via crafted OSPF LSA opaque area updates.
Is there a workaround for CVE-2015-6432?
There are no specific workarounds for CVE-2015-6432; the recommended action is to update to a secure version.