CVE-2015-4201

UnknownEPSS 2.96%

Last modified

CVE-2015-4201 is a vulnerability of currently unknown severity. The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header, aka Bug ID CSCut68058.. EPSS estimates a 2.96% chance of exploitation in the next 30 days.

Description

The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header, aka Bug ID CSCut68058.

Metrics

EPSS Probability
2.96%

85.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoAsr 5000 Series Software17.2.0.59184
CiscoAsr 5000 Series Software18.0.l059219

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-4201?
The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header, aka Bug ID CSCut68058.
How severe is CVE-2015-4201?
Severity scoring for CVE-2015-4201 is pending analysis. The EPSS model estimates a 2.96% probability of exploitation in the next 30 days.
How do I fix CVE-2015-4201?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-4201?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST