{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T07:16:38Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20150831-CVE-2015-6274","slug":"cisco-sa-20150831-cve-2015-6274","vendor":"Cisco","title":"Cisco ASR 1000 Series Aggregation Services Routers Data-Plane Processing Denial of Service Vulnerability","summary":"A vulnerability in the Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to the processing of excessive number of IPv4 packets that require fragmentation and reassembly. An attacker could exploit ths vulnerability by sending an excessive number of fragmented packets, causing high Cisco QuantumFlow Processor (QFP) CPU utilization in the Embedded Services Processor (ESP). Cisco has confirmed the vulnerability; however, software updates are not available. To exploit this vulnerability, the attacker must send an excessive number of fragmented packets to the targeted system, making exploitation more difficult in environments that restrict access from untrusted sources Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.","severity":"Medium","published_at":"2015-08-31T23:19:04Z","updated_at":"2015-08-31T23:19:04Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150831-CVE-2015-6274","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20150831-CVE-2015-6274/csaf/Cisco-SA-20150831-CVE-2015-6274.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.01744},"cves":[{"id":"CVE-2015-6274","kev":false,"epss":{"score":0.01744,"percentile":0.75289,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"}}],"public_evidence":[{"product":{"name":"Cisco ASR 1000 Series Aggregation Services Routers","slug":"cisco-asr-1000-series-aggregation-services-routers","vendor":"Cisco"},"cve":{"id":"CVE-2015-6274"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-19T23:13:47Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco ASR 1000 Series Aggregation Services Routers","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.01744,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"},"published_at":"2015-08-31T23:19:04Z","updated_at":"2015-08-31T23:19:04Z","advisory_updated_at":"2015-08-31T23:19:04Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150831-CVE-2015-6274","row_display_order":1}]}