4
CVSSv2

CVE-2015-4195

Published: 19/06/2015 Updated: 28/12/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

A vulnerability in Cisco IOS XR Software could allow an authenticated, remote malicious user to cause a denial of service (DoS) condition. The vulnerability is due to an error that could occur in the affected software when an SSH connection is disconnected from an affected device. An authenticated, remote attacker could exploit the vulnerability to cause the vty to become unreachable and cause further SSH or Telnet connections to the device to fail, resulting in a DoS condition. Cisco has confirmed the vulnerability and released software updates. To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement reduces the likelihood of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xr 5.1.1.k9sec

Vendor Advisories

A vulnerability in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition The vulnerability is due to an error that could occur in the affected software when an SSH connection is disconnected from an affected device An authenticated, remote attacker could exploit the vulnerability to caus ...