← Back

CVE-2015-4293

nvd nist
Published: Jul 30, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The packet-reassembly implementation in Cisco IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (CPU consumption or packet loss) via fragmented (1) IPv4 or (2) IPv6 packets that trigger ATTN-3-SYNC_TIMEOUT errors after reassembly failures, aka Bug ID CSCuo37957.

Affected (29)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 2.1.0
Version 2.1.1
Version 2.1.2
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.3.0
Version 2.3.0t
Version 2.3.1t
Version 2.3.2
Version 2.4.0
Version 2.4.1
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 2.6.0
Version 2.6.1
Version 2.6.2
Version 3.10s.0
Version 3.10s.0a
Version 3.10s.1
Version 3.10s.2
Version 3.10s.3
Version 3.11s.0
Version 3.11s.1
Version 3.11s.2
Version 3.12s.0
Version 3.12s.1
Version 3.13s.0

Related CWEs

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.