Cisco IOS/ios xe IPv6 listener Denial of Service Vulnerability (CVE-2015-6278)
Cisco IOS/ios xe IPv6 listener Denial of Service Vulnerability (CVE-2015-6278)
Release date:
Updated on:
Affected Systems:
Cisco IOS
Cisco IOS XE
Description:
CVE (CAN) ID: CVE-2015-6278
Cisco IOS is an interconnected network operating system used on most Cisco system routers and network switches.
Cisco IOS and ios xe Software have a security vulnerability in IPv6 monitoring. unauthenticated remote attackers can exploit this vulnerability to overload affected devices. This vulnerability occurs because CPPr is invalid for a specific IPv6 ND packet.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150923-fhs
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20150923-fhs) and patches for this:
Cisco-sa-20150923-fhs: Cisco IOS and ios xe Software IPv6 First Hop Security Denial of Service Vulnerabilities
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150923-fhs
This article permanently updates the link address: