CVE-2015-0639 describes a denial-of-service vulnerability in Cisco IOS XE versions 3.6 through 3.15, specifically impacting the Common Flow Table (CFT) feature when MMON or NBAR is enabled. Remote attackers can trigger a device reload by sending malformed IPv6 packets with IPv4 UDP encapsulation. This vulnerability has a CVSS score of 7.8, indicating a high severity with a network-based attack vector, low attack complexity, and a complete impact on availability. While no known public exploits exist in Metasploit, Nuclei, or ExploitDB, and it is not listed in the KEV catalog, it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.6sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.6s:*:*:*:*:*:*:* | ||
3.6s.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.6s.0:*:*:*:*:*:*:* | ||
3.6s.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.6s.1:*:*:*:*:*:*:* | ||
3.6s.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.6s.2:*:*:*:*:*:*:* | ||
3.7sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.7s:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.