MEDIUM · 6.1

CVE-2015-4243

The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Reque...

Vulnerability Description

The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty94202.

CVSS Score

6.1

MEDIUM

AV:A/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoIos Xe3.5.0s
CiscoAsr 1001-
CiscoAsr 1001-X-
CiscoAsr 1002-
CiscoAsr 1002-X-
CiscoAsr 1004-
CiscoAsr 1006-
CiscoAsr 1013-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-4243?

CVE-2015-4243 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Reque...

How severe is CVE-2015-4243?

CVE-2015-4243 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-4243?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco Asr 1001, Cisco Asr 1001-X, Cisco Asr 1002, Cisco Asr 1002-X.