Vulnslist

find the latest Cisco vulnerabilities

Cisco ASR 5000 and ASR 5500 TACACS Denial of Service Vulnerability

cisco-sa-20151012-asr · Medium · Published · Updated

A vulnerability in the TACACS protocol implementation of the Cisco Aggregation Services Router (ASR) 5000 and ASR 5500 (ASR5K) System Software could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition because the vpnmgr process restarts.   The vulnerability is due to improper input validation of the TACACS packet header. An attacker could exploit this vulnerability by sending a crafted TACACS packet to the device. An exploit could allow the attacker to cause a partial DoS condition because the vpnmgr process could restart when parsing the crafted TACACS packet. Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151012-asr

Workarounds

No workarounds are available.

CVEsCVE-2015-6334
Cisco Bug IDsCSCuw01984, CSCuw01985
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C
Product Names From Source
Cisco ASR 5000 Series Software

Related Products

Product CVE Evidence
Cisco ASR 5000 Series Software CVE-2015-6334 Cisco OpenVuln