CVE-2015-6392

HIGH

Cisco NX-OS 4.1-7.3 and 11.0-11.2 - Denial of Service via Crafted IPv4 DHCP Packets

Title source: llm
STIX 2.1

Description

Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) smart relay agent, aka Bug IDs CSCuq24603, CSCur93159, CSCus21693, and CSCut76171.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93406
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036948

Scores

CVSS v3 7.5
EPSS 0.0191
EPSS Percentile 77.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399
Status published
Products (50)
cisco/nx-os 4.1.\(2\)
cisco/nx-os 4.1.\(3\)
cisco/nx-os 4.1.\(4\)
cisco/nx-os 4.1.\(5\)
cisco/nx-os 4.2\(3\)
cisco/nx-os 4.2\(4\)
cisco/nx-os 4.2\(6\)
cisco/nx-os 4.2\(8\)
cisco/nx-os 4.2.\(2a\)
cisco/nx-os 5.0\(2a\)
... and 40 more
Published Oct 06, 2016
Tracked Since Feb 18, 2026