CVE-2015-0646

Cisco IOS XE < 3.10.5S/3.12.3S & IOS 12.2-15.4 DoS via Crafted TCP Packets

Title source: llm
STIX 2.1

Description

Memory leak in the TCP input module in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.3.xXO, 3.5.xE, 3.6.xE, 3.8.xS through 3.10.xS before 3.10.5S, and 3.11.xS and 3.12.xS before 3.12.3S allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted TCP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCum94811.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73340
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031980

Scores

EPSS 0.0378
EPSS Percentile 88.8%

Details

CWE
CWE-399
Status published
Products (36)
cisco/ios 12.2
cisco/ios 12.4
cisco/ios 15.0
cisco/ios 15.1
cisco/ios 15.2
cisco/ios 15.3
cisco/ios 15.4
cisco/ios_xe 3.3xo.0
cisco/ios_xe 3.3xo.1
cisco/ios_xe 3.3xo.2
... and 26 more
Published Mar 26, 2015
Tracked Since Feb 18, 2026