HIGH · 7.1

CVE-2015-0688

Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.32...

Vulnerability Description

Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.

CVSS Score

7.1

HIGH

AV:N/AC:M/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoIos Xe13.10.2s
CiscoAsr 1001All versions
CiscoAsr 1001-XAll versions
CiscoAsr 1002All versions
CiscoAsr 1002-XAll versions
CiscoAsr 1004All versions
CiscoAsr 1006All versions
CiscoAsr 1013All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0688?

CVE-2015-0688 is a vulnerability with a CVSS score of 7.1 (HIGH). Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.32...

How severe is CVE-2015-0688?

CVE-2015-0688 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0688?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco Asr 1001, Cisco Asr 1001-X, Cisco Asr 1002, Cisco Asr 1002-X.