CVE-2015-0688
Severity CVSS v4.0:
Pending analysis
Type:
CWE-399
Resource Management Errors
Publication date:
04/04/2015
Last modified:
12/04/2025
Description
Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.
Impact
Base Score 2.0
7.10
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cisco:ios_xe:13.10.2s:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1001:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1001-x:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1002:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1002-x:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1004:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1006:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1013:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



