CVE-2015-6398 describes a denial-of-service vulnerability affecting Cisco Nexus 9000 switches operating in Application Centric Infrastructure (ACI) Mode with software versions prior to 11.0(1c). An unauthenticated remote attacker can trigger a device reload by sending a specially crafted IPv4 ICMP packet containing the IP Record Route option. This vulnerability has a CVSSv3 score of 7.5 (HIGH), indicating a high impact on availability with low attack complexity and no user interaction required. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available, the vulnerability has garnered some community discussion and media coverage, though it is not listed in CISA's KEV catalog as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.50\(aazi.0\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.