6.1
CVSSv2

CVE-2015-4243

Published: 08/07/2015 Updated: 29/12/2016
CVSS v2 Base Score: 6.1 | Impact Score: 6.9 | Exploitability Score: 6.5
VMScore: 543
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote malicious users to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty94202.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios_xe 3.5.0s

Vendor Advisories

A vulnerability in PPP over Ethernet (PPPoE) processing on Cisco IOS XE for Cisco 1000 Series ASR routers could allow an unauthenticated, adjacent attacker to cause a reload of the affected device The vulnerability is due to improper processing of malformed PPPoE Active Discovery Request (PADR) packets An attacker could exploit this vulnerabilit ...