CVE-2015-0638
UnknownEPSS 1.69%
Last modified
CVE-2015-0638 is a vulnerability of currently unknown severity. Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.. EPSS estimates a 1.69% chance of exploitation in the next 30 days.
Description
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.2\(33\)ird1 |
| Cisco | Ios | 12.2\(33\)ire3 |
| Cisco | Ios | 12.2\(33\)sxi4b |
| Cisco | Ios | 12.2\(44\)sq1 |
| Cisco | Ios | 12.4\(25e\)jam1 |
| Cisco | Ios | 12.4\(25e\)jap1m |
| Cisco | Ios | 12.4\(25e\)jaz1 |
| Cisco | Ios | 15.0\(2\)ed1 |
| Cisco | Ios | 15.2\(1\)ex |
| Cisco | Ios | 15.2\(2\)gc |
| Cisco | Ios | 15.2\(2\)ja |
| Cisco | Ios | 15.2\(2\)ja1 |
| Cisco | Ios | 15.2\(2\)jax |
| Cisco | Ios | 15.2\(2\)jax1 |
| Cisco | Ios | 15.2\(2\)jb |
| Cisco | Ios | 15.2\(2\)jb1 |
| Cisco | Ios | 15.2\(2\)jb2 |
| Cisco | Ios | 15.2\(2\)jb3 |
| Cisco | Ios | 15.2\(2\)jb4 |
| Cisco | Ios | 15.2\(2\)jn1 |
| Cisco | Ios | 15.2\(2\)jn2 |
| Cisco | Ios | 15.2\(2\)t |
| Cisco | Ios | 15.2\(2\)t1 |
| Cisco | Ios | 15.2\(2\)t2 |
| Cisco | Ios | 15.2\(2\)t3 |
| Cisco | Ios | 15.2\(2\)t4 |
| Cisco | Ios | 15.2\(3\)t |
| Cisco | Ios | 15.3\(2\)s2 |
| Cisco | Ios | 15.3\(3\)ja1n |
| Cisco | Ios | 15.3\(3\)jab1 |
| Cisco | Ios | 15.3\(3\)jn |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0638?
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.
How severe is CVE-2015-0638?
Severity scoring for CVE-2015-0638 is pending analysis. The EPSS model estimates a 1.69% probability of exploitation in the next 30 days.
How do I fix CVE-2015-0638?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2015-0638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
