CVE Vulnerabilities

CVE-2015-6432

Published: Jan 05, 2016 | Modified: Dec 07, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PCEs) for OSPF LSA opaque area updates, which allows remote attackers to cause a denial of service (device reload) via a crafted update, aka Bug ID CSCuw83486.

Affected Software

Name Vendor Start Version End Version
Ios_xr Cisco 4.2.0 (including) 4.2.0 (including)
Ios_xr Cisco 4.3.0 (including) 4.3.0 (including)
Ios_xr Cisco 5.0.0 (including) 5.0.0 (including)
Ios_xr Cisco 5.1.0 (including) 5.1.0 (including)
Ios_xr Cisco 5.2.0 (including) 5.2.0 (including)
Ios_xr Cisco 5.2.2 (including) 5.2.2 (including)
Ios_xr Cisco 5.2.4 (including) 5.2.4 (including)
Ios_xr Cisco 5.3.0 (including) 5.3.0 (including)
Ios_xr Cisco 5.3.2 (including) 5.3.2 (including)

References