CVE-2015-4291 describes a denial-of-service vulnerability in Cisco IOS XE versions 2.x and 2.5.x on ASR 1000 devices. Remote attackers can trigger an Embedded Services Processor crash by sending a crafted series of fragmented IPv4 or IPv6 packets. With a CVSS score of 7.8 (High), this vulnerability is easily exploitable over the network without authentication, leading to a complete loss of availability. While no public exploit code or active exploitation is noted, the vulnerability has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.1.0:*:*:*:*:*:*:* | ||
2.1.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.1.1:*:*:*:*:*:*:* | ||
2.1.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.1.2:*:*:*:*:*:*:* | ||
2.2.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.2.1:*:*:*:*:*:*:* | ||
2.2.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.