CVE-2015-0638
UnknownEPSS 1.69%
Last modified
CVE-2015-0638 is a vulnerability of currently unknown severity. Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.. EPSS estimates a 1.69% chance of exploitation in the next 30 days.
Description
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.2\(33\)ird1 |
| Cisco | Ios | 12.2\(33\)ire3 |
| Cisco | Ios | 12.2\(33\)sxi4b |
| Cisco | Ios | 12.2\(44\)sq1 |
| Cisco | Ios | 12.4\(25e\)jam1 |
| Cisco | Ios | 12.4\(25e\)jap1m |
| Cisco | Ios | 12.4\(25e\)jaz1 |
| Cisco | Ios | 15.0\(2\)ed1 |
| Cisco | Ios | 15.2\(1\)ex |
| Cisco | Ios | 15.2\(2\)gc |
| Cisco | Ios | 15.2\(2\)ja |
| Cisco | Ios | 15.2\(2\)ja1 |
| Cisco | Ios | 15.2\(2\)jax |
| Cisco | Ios | 15.2\(2\)jax1 |
| Cisco | Ios | 15.2\(2\)jb |
| Cisco | Ios | 15.2\(2\)jb1 |
| Cisco | Ios | 15.2\(2\)jb2 |
| Cisco | Ios | 15.2\(2\)jb3 |
| Cisco | Ios | 15.2\(2\)jb4 |
| Cisco | Ios | 15.2\(2\)jn1 |
| Cisco | Ios | 15.2\(2\)jn2 |
| Cisco | Ios | 15.2\(2\)t |
| Cisco | Ios | 15.2\(2\)t1 |
| Cisco | Ios | 15.2\(2\)t2 |
| Cisco | Ios | 15.2\(2\)t3 |
| Cisco | Ios | 15.2\(2\)t4 |
| Cisco | Ios | 15.2\(3\)t |
| Cisco | Ios | 15.3\(2\)s2 |
| Cisco | Ios | 15.3\(3\)ja1n |
| Cisco | Ios | 15.3\(3\)jab1 |
| Cisco | Ios | 15.3\(3\)jn |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0638?
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.
How severe is CVE-2015-0638?
Severity scoring for CVE-2015-0638 is pending analysis. The EPSS model estimates a 1.69% probability of exploitation in the next 30 days.
How do I fix CVE-2015-0638?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-0632Race condition in the Neighbor Discovery (ND) protocol imple…
- CVE-2015-0633The Integrated Management Controller (IMC) in Cisco Unified …
- CVE-2015-0634Cross-site scripting (XSS) vulnerability in the administrati…
- CVE-2015-0635The Autonomic Networking Infrastructure (ANI) implementation…
- CVE-2015-0636The Autonomic Networking Infrastructure (ANI) implementation…
- CVE-2015-0637The Autonomic Networking Infrastructure (ANI) implementation…
- CVE-2015-0639The Common Flow Table (CFT) feature in Cisco IOS XE 3.6 and …
- CVE-2015-0640The high-speed logging (HSL) feature in Cisco IOS XE 2.x and…
- CVE-2015-0641Cisco IOS XE 2.x and 3.x before 3.9.0S, 3.10 before 3.10.0S,…
- CVE-2015-0642Cisco IOS 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and 15.4 and I…
- CVE-2015-0643Cisco IOS 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and 15.4 and I…
- CVE-2015-0644AppNav in Cisco IOS XE 3.8 through 3.10 before 3.10.3S, 3.11…
Are you affected by CVE-2015-0638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
