CVE-2015-4293 describes a denial-of-service vulnerability in Cisco IOS XE versions 3.13S and earlier, affecting ASR routers. Remote attackers can exploit a flaw in the packet-reassembly implementation by sending fragmented IPv4 or IPv6 packets, leading to high CPU consumption or packet loss due to reassembly failures. This vulnerability has a CVSS score of 5.0, indicating a network-based attack with low complexity and no authentication required, resulting in partial availability impact. There is no evidence of active exploitation, nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB. While it has received limited community discussion and media coverage, it is not listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.4.1:*:*:*:*:*:*:* | ||
2.5.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.5.0:*:*:*:*:*:*:* | ||
2.5.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.5.1:*:*:*:*:*:*:* | ||
2.5.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.5.2:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:2.6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.