Cisco ASR 5500 SAE gateway Denial of Service Vulnerability (CVE-2015-6351)
Cisco ASR 5500 SAE gateway Denial of Service Vulnerability (CVE-2015-6351)
Release date:
Updated on:
Affected Systems:
Cisco ASR 5500 19.2.0
Cisco ASR 5500 19.1.0.61559
Description:
CVE (CAN) ID: CVE-2015-6351
The Cisco ASR 5000 series is a carrier-level platform for deploying high-demand 3G networks and migrating to long-term evolution (LTE) networks.
For Cisco ASR 5500 SAE Gateway devices, software versions 19.1.0.61559 and 19.2.0, a security vulnerability exists in the input packet processing program of the Border Gateway Protocol. unauthenticated remote attackers exploit this vulnerability to cause DOS.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151028-asr
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20151028-asr) and patches for this:
Cisco-sa-20151028-asr: Cisco ASR 5500 SAE Gateway BGP Denial of Service Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151028-asr
This article permanently updates the link address: