5
CVSSv2

CVE-2015-6429

Published: 19/12/2015 Updated: 07/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The IKEv1 state machine in Cisco IOS 15.4 up to and including 15.6 and IOS XE 3.15 up to and including 3.17 allows remote malicious users to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka Bug ID CSCuw08236.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 15.5\\(2\\)t

cisco ios 15.5\\(3\\)m1

cisco ios 15.5\\(1\\)t

cisco ios 15.5\\(3\\)m

cisco ios 15.5\\(3\\)s

cisco ios 15.5\\(2\\)s

cisco ios 15.6\\(0.17\\)t

cisco ios 15.4\\(3\\)s

cisco ios 15.5\\(1\\)s

cisco ios 15.5\\(3\\)s1

cisco ios 15.6\\(1\\)t0a

cisco ios xe 3.16s.1

cisco ios xe 3.15s.2

cisco ios xe 3.17s.1

cisco ios xe 3.17s.0

cisco ios xe 3.16s.0

cisco ios xe 3.15s.1

cisco ios xe 3.15s.0

Vendor Advisories

A vulnerability in the Internet Key Exchange (IKEv1) state machine of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to tear down valid IPsec connections, resulting in a partial denial of service (DoS) condition The vulnerability is due to insufficient condition checks in the IKEv1 state machine An attacker c ...