CVE-2015-6277

UnknownEPSS 0.88%

Last modified

CVE-2015-6277 is a vulnerability of currently unknown severity. The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1, Nexus 9000 devices 7.3(0)ZD(0.61), and MDS 9000 devices 7.0(0)HSK(0.353) and SAN-OS NX-OS on MDS 9000 devices 7.0(0)HSK(0.353) allows remote attackers to cause a denial of service (ARP process restart) via crafted packet-header fields, aka Bug ID CSCut25292.. EPSS estimates a 0.88% chance of exploitation in the next 30 days.

Description

The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1, Nexus 9000 devices 7.3(0)ZD(0.61), and MDS 9000 devices 7.0(0)HSK(0.353) and SAN-OS NX-OS on MDS 9000 devices 7.0(0)HSK(0.353) allows remote attackers to cause a denial of service (ARP process restart) via crafted packet-header fields, aka Bug ID CSCut25292.

Metrics

EPSS Probability
0.88%

54.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoNx-Os7.3\(0\)zd\(0.47\)
CiscoNx-Os4.1\(2\)e1
CiscoNx-Os7.0\(0\)hsk\(0.353\)
CiscoSan-Os7.0\(0\)hsk\(0.353\)
CiscoMds 9000All versions
CiscoNx-Os7.3\(0\)zd\(0.61\)
Cisco1000v5.2\(1\)sv3\(1.4\)

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-6277?
The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1, Nexus 9000 devices 7.3(0)ZD(0.61), and MDS 9000 devices 7.0(0)HSK(0.353) and SAN-OS NX-OS on MDS 9000 devices 7.0(0)HSK(0.353) allows remote attackers to cause a denial of service (ARP process restart) via crafted packet-header fields, aka Bug ID CSCut25292.
How severe is CVE-2015-6277?
Severity scoring for CVE-2015-6277 is pending analysis. The EPSS model estimates a 0.88% probability of exploitation in the next 30 days.
How do I fix CVE-2015-6277?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-6277?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST