7.1
CVSSv2

CVE-2015-0638

Published: 26/03/2015 Updated: 04/09/2015
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote malicious users to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 12.2\\(33\\)sxi4b

cisco ios 15.2\\(2\\)t1

cisco ios 15.2\\(2\\)jb1

cisco ios 15.2\\(2\\)jax

cisco ios 15.2\\(2\\)jn1

cisco ios 15.2\\(2\\)jn2

cisco ios 15.2\\(2\\)jax1

cisco ios 15.3\\(3\\)ja1n

cisco ios 12.2\\(44\\)sq1

cisco ios 15.2\\(2\\)t

cisco ios 15.2\\(3\\)t

cisco ios 12.2\\(33\\)ire3

cisco ios 12.4\\(25e\\)jaz1

cisco ios 12.4\\(25e\\)jam1

cisco ios 15.3\\(2\\)s2

cisco ios 15.2\\(2\\)jb2

cisco ios 15.2\\(2\\)t3

cisco ios 15.2\\(2\\)t4

cisco ios 15.2\\(2\\)gc

cisco ios 15.2\\(2\\)ja

cisco ios 15.2\\(2\\)jb3

cisco ios 15.2\\(2\\)jb4

cisco ios 15.3\\(3\\)jn

cisco ios 15.3\\(3\\)jab1

cisco ios 12.2\\(33\\)ird1

cisco ios 15.2\\(2\\)t2

cisco ios 15.2\\(2\\)ja1

cisco ios 15.2\\(2\\)jb

cisco ios 15.2\\(1\\)ex

cisco ios 15.0\\(2\\)ed1

cisco ios 12.4\\(25e\\)jap1m

Vendor Advisories

A vulnerability within the virtual routing and forwarding (VRF) subsystem of Cisco IOS software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition The vulnerability is due to a failure to properly process malicious ICMP version 4 (ICMPv4) messages received on a VRF-enabled interface An attacker could exp ...