CVE-2015-4291
Cisco IOS XE 2.x < 2.4.3 and 2.5.x < 2.5.1 - Denial of Service via Fragmented IPv4/IPv6 Packets
Title source: llmDescription
Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1033131
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150730-asr1k
Scores
EPSS
0.0198
EPSS Percentile
78.5%
Details
CWE
CWE-399
Status
published
Products (13)
cisco/ios_xe
2.1.0
cisco/ios_xe
2.1.1
cisco/ios_xe
2.1.2
cisco/ios_xe
2.2.1
cisco/ios_xe
2.2.2
cisco/ios_xe
2.2.3
cisco/ios_xe
2.3.0
cisco/ios_xe
2.3.0t
cisco/ios_xe
2.3.1t
cisco/ios_xe
2.3.2
... and 3 more
Published
Aug 01, 2015
Tracked Since
Feb 18, 2026