CVE-2015-4285
Last modified
CVE-2015-4285 is a vulnerability of currently unknown severity. The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports continuously, aka Bug ID CSCur88273.. EPSS estimates a 1.74% chance of exploitation in the next 30 days.
Description
The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports continuously, aka Bug ID CSCur88273.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | 5.1.2 |
| Cisco | Ios Xr | 5.1.3 |
| Cisco | Ios Xr | 5.2.1 |
| Cisco | Ios Xr | 5.2.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-4285?
How severe is CVE-2015-4285?
How do I fix CVE-2015-4285?
Are you affected by CVE-2015-4285?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
