CVE-2015-4285

Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, 5.2.2 - Denial of Service via LPTS Port Handling

Title source: llm
STIX 2.1

Description

The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports continuously, aka Bug ID CSCur88273.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory x_refsource_cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=40068
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033043

Scores

EPSS 0.0174
EPSS Percentile 75.4%

Details

CWE
CWE-399
Status published
Products (4)
cisco/ios_xr 5.1.2
cisco/ios_xr 5.1.3
cisco/ios_xr 5.2.1
cisco/ios_xr 5.2.2
Published Jul 23, 2015
Tracked Since Feb 18, 2026