CVE-2015-0635 describes a vulnerability in the Autonomic Networking Infrastructure (ANI) implementation across various versions of Cisco IOS and IOS XE. This flaw allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses using crafted AN messages. Successful exploitation can lead to a bypass of device and node access restrictions or a denial of service by disrupting domain access. The vulnerability carries a CVSS score of 9.0, indicating critical severity. It is easily exploitable over the network with low attack complexity, requiring no authentication. The potential impact includes partial confidentiality, partial integrity, and complete availability compromise. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article identified, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.10s.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.10s.0:*:*:*:*:*:*:* | ||
3.10s.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.10s.1:*:*:*:*:*:*:* | ||
3.10s.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.10s.2:*:*:*:*:*:*:* | ||
3.10s.3CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.10s.3:*:*:*:*:*:*:* | ||
3.10s.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.10s.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.