CVE-2015-0769 describes a denial-of-service vulnerability in Cisco IOS XR versions 4.0.1 through 4.2.0, specifically impacting the CRS-3 Carrier Routing System. Remote attackers can exploit this flaw by sending crafted IPv6 extension headers, leading to an NPU ASIC scan and subsequent line-card reload. This vulnerability carries a high severity CVSS score of 7.8, indicating a network-based attack with low complexity, requiring no authentication, and resulting in complete system availability loss. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr_software:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr_software:4.0.2:*:*:*:*:*:*:* | ||
4.0.3CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr_software:4.0.3:*:*:*:*:*:*:* | ||
4.0.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr_software:4.0.4:*:*:*:*:*:*:* | ||
4.0.11CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr_software:4.0.11:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.