CVE-2015-6432

EUVD-2015-6373
Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PCEs) for OSPF LSA opaque area updates, which allows remote attackers to cause a denial of service (device reload) via a crafted update, aka Bug ID CSCuw83486.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
ciscoios_xr
4.2.0
ciscoios_xr
4.3.0
ciscoios_xr
5.0.0
ciscoios_xr
5.1.0
ciscoios_xr
5.2.0
ciscoios_xr
5.2.2
ciscoios_xr
5.2.4
ciscoios_xr
5.3.0
ciscoios_xr
5.3.2
𝑥
= Vulnerable software versions
Common Weakness Enumeration