7.5
CVSSv3

CVE-2015-6432

Published: 05/01/2016 Updated: 07/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PCEs) for OSPF LSA opaque area updates, which allows remote malicious users to cause a denial of service (device reload) via a crafted update, aka Bug ID CSCuw83486.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xr 5.0.0

cisco ios xr 5.3.2

cisco ios xr 4.3.0

cisco ios xr 4.2.0

cisco ios xr 5.2.4

cisco ios xr 5.3.0

cisco ios xr 5.2.2

cisco ios xr 5.2.0

cisco ios xr 5.1.0

Vendor Advisories

A vulnerability in Open Shortest Path First (OSPF) Link State Advertisement (LSA) handling by Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition The vulnerability is due to the number of OSPF Path Computation Elements (PCEs) that are configured for an OSPF LSA opaque area update An ...