HIGH · 7.1

CVE-2015-0631

Race condition in the SSL implementation on Cisco Intrusion Prevention System (IPS) devices allows remote attackers to cause a denial of service by making many management-interface HTTPS connections d...

Vulnerability Description

Race condition in the SSL implementation on Cisco Intrusion Prevention System (IPS) devices allows remote attackers to cause a denial of service by making many management-interface HTTPS connections during the key-regeneration phase of an upgrade, aka Bug ID CSCui25688.

CVSS Score

7.1

HIGH

AV:N/AC:M/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoIps Sensor Software7.2\(1\)e4
CiscoIds 4210All versions
CiscoIds 4215All versions
CiscoIds 4220All versions
CiscoIds 4230All versions
CiscoIds 4235All versions
CiscoIds 4250All versions
CiscoIds 4250 XlAll versions
CiscoIps 4240All versions
CiscoIps 4255All versions
CiscoIps 4260All versions
CiscoIps 4270All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0631?

CVE-2015-0631 is a vulnerability with a CVSS score of 7.1 (HIGH). Race condition in the SSL implementation on Cisco Intrusion Prevention System (IPS) devices allows remote attackers to cause a denial of service by making many management-interface HTTPS connections d...

How severe is CVE-2015-0631?

CVE-2015-0631 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0631?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ips Sensor Software, Cisco Ids 4210, Cisco Ids 4215, Cisco Ids 4220, Cisco Ids 4230.