CVE-2015-6273

Cisco IOS XE - Denial of Service via Crafted IP Packets

Title source: llm
STIX 2.1

Description

Cisco IOS XE before 3.1.2S on ASR 1000 devices mishandles the automatic setup of Virtual Fragment Reassembly (VFR) by certain firewall and NAT components, which allows remote attackers to cause a denial of service (Embedded Services Processor crash) via crafted IP packets, aka Bug IDs CSCtf87624, CSCte93229, CSCtd19103, and CSCti63623.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033408
Vendor Advisory vendor-advisory x_refsource_cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=40690

Scores

EPSS 0.0191
EPSS Percentile 77.6%

Details

CWE
CWE-399
Status published
Products (5)
cisco/ios_xe 2.2.1
cisco/ios_xe 2.2.2
cisco/ios_xe 2.2.3
cisco/ios_xe 3.1.0s
cisco/ios_xe 3.1.1s
Published Aug 29, 2015
Tracked Since Feb 18, 2026