6.1
CVSSv2

CVE-2015-6359

Published: 15/12/2015 Updated: 07/12/2016
CVSS v2 Base Score: 6.1 | Impact Score: 6.9 | Exploitability Score: 6.5
VMScore: 543
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote malicious users to cause a denial of service (memory consumption or device crash) via a flood of crafted ND messages, aka Bug ID CSCup28217.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 15.2\\(4\\)st

cisco ios 15.2\\(4\\)pi

cisco ios 15.2\\(4\\)e

cisco ios 15.3\\(3\\)s0.1

cisco ios 15.2\\(5\\)st

Vendor Advisories

A vulnerability in the IPv6 neighbor discovery (ND) handling of Cisco IOS XE Software on ASR platforms could allow an unauthenticated, adjacent attacker to cause an affected device to crash The vulnerability is due to insufficient bounds on internal tables An attacker could exploit this vulnerability by flooding an adjacent IOS XE device with sp ...