CVE-2015-0688

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
04/04/2015
Last modified:
12/04/2025

Description

Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:ios_xe:13.10.2s:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_1001:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_1001-x:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_1002:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_1002-x:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_1004:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_1006:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_1013:*:*:*:*:*:*:*:*