CVE-2015-6392
HIGHCisco NX-OS 4.1-7.3 and 11.0-11.2 - Denial of Service via Crafted IPv4 DHCP Packets
Title source: llmDescription
Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) smart relay agent, aka Bug IDs CSCuq24603, CSCur93159, CSCus21693, and CSCut76171.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/93406
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-dhcp1
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1036948
Scores
CVSS v3
7.5
EPSS
0.0191
EPSS Percentile
77.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-399
Status
published
Products (50)
cisco/nx-os
4.1.\(2\)
cisco/nx-os
4.1.\(3\)
cisco/nx-os
4.1.\(4\)
cisco/nx-os
4.1.\(5\)
cisco/nx-os
4.2\(3\)
cisco/nx-os
4.2\(4\)
cisco/nx-os
4.2\(6\)
cisco/nx-os
4.2\(8\)
cisco/nx-os
4.2.\(2a\)
cisco/nx-os
5.0\(2a\)
... and 40 more
Published
Oct 06, 2016
Tracked Since
Feb 18, 2026