CVE-2015-0649
UnknownEPSS 2.14%
Last modified
CVE-2015-0649 is a vulnerability of currently unknown severity. Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.. EPSS estimates a 2.14% chance of exploitation in the next 30 days.
Description
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.2\(33\)ird1 |
| Cisco | Ios | 12.2\(33\)ire3 |
| Cisco | Ios | 12.2\(33\)sxi4b |
| Cisco | Ios | 12.2\(44\)sq1 |
| Cisco | Ios | 12.2\(52\)se |
| Cisco | Ios | 12.2\(52\)se1 |
| Cisco | Ios | 12.2\(55\)se |
| Cisco | Ios | 12.2\(55\)se3 |
| Cisco | Ios | 12.2\(55\)se4 |
| Cisco | Ios | 12.2\(55\)se5 |
| Cisco | Ios | 12.2\(55\)se6 |
| Cisco | Ios | 12.2\(55\)se7 |
| Cisco | Ios | 12.2\(55\)se8 |
| Cisco | Ios | 12.2\(55\)se9 |
| Cisco | Ios | 12.2\(58\)se2 |
| Cisco | Ios | 12.4\(25e\)jam1 |
| Cisco | Ios | 12.4\(25e\)jap1m |
| Cisco | Ios | 12.4\(25e\)jaz1 |
| Cisco | Ios | 15.0\(1\)ey |
| Cisco | Ios | 15.0\(1\)ey1 |
| Cisco | Ios | 15.0\(1\)ey2 |
| Cisco | Ios | 15.0\(2\)eb |
| Cisco | Ios | 15.0\(2\)ed1 |
| Cisco | Ios | 15.0\(2\)ey |
| Cisco | Ios | 15.0\(2\)ey1 |
| Cisco | Ios | 15.0\(2\)ey2 |
| Cisco | Ios | 15.0\(2\)ey3 |
| Cisco | Ios | 15.0\(2\)se |
| Cisco | Ios | 15.0\(2\)se1 |
| Cisco | Ios | 15.0\(2\)se2 |
| Cisco | Ios | 15.0\(2\)se3 |
| Cisco | Ios | 15.0\(2\)se4 |
| Cisco | Ios | 15.0\(2\)se5 |
| Cisco | Ios | 15.0\(2\)se6 |
| Cisco | Ios | 15.0\(2\)se7 |
| Cisco | Ios | 15.2\(1\)ex |
| Cisco | Ios | 15.2\(1\)ey |
| Cisco | Ios | 15.2\(2\)e |
| Cisco | Ios | 15.2\(2\)e1 |
| Cisco | Ios | 15.2\(2\)jb1 |
| Cisco | Ios | 15.3\(2\)s2 |
| Cisco | Ios | 15.3\(3\)ja1n |
| Cisco | Ios | 15.3\(3\)jab1 |
| Cisco | Ios | 15.3\(3\)jn |
| Cisco | Ios | 15.3\(3\)jnb |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0649?
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.
How severe is CVE-2015-0649?
Severity scoring for CVE-2015-0649 is pending analysis. The EPSS model estimates a 2.14% probability of exploitation in the next 30 days.
How do I fix CVE-2015-0649?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-0643Cisco IOS 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and 15.4 and I…
- CVE-2015-0644AppNav in Cisco IOS XE 3.8 through 3.10 before 3.10.3S, 3.11…
- CVE-2015-0645The Layer 4 Redirect (L4R) feature in Cisco IOS XE 2.x and 3…
- CVE-2015-0646Memory leak in the TCP input module in Cisco IOS 12.2, 12.4,…
- CVE-2015-0647Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote att…
- CVE-2015-0648Memory leak in Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 al…
- CVE-2015-0650The Service Discovery Gateway (aka mDNS Gateway) in Cisco IO…
- CVE-2015-0651Cross-site request forgery (CSRF) vulnerability in the web G…
- CVE-2015-0652The Session Description Protocol (SDP) implementation in Cis…
- CVE-2015-0653The management interface in Cisco TelePresence Video Communi…
- CVE-2015-0654Race condition in the TLS implementation in MainApp in the m…
- CVE-2015-0655Cross-site scripting (XSS) vulnerability in Unified Web Inte…
Are you affected by CVE-2015-0649?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
