CVE-2015-4285
Severity CVSS v4.0:
Pending analysis
Type:
CWE-399
Resource Management Errors
Publication date:
23/07/2015
Last modified:
12/04/2025
Description
The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports continuously, aka Bug ID CSCur88273.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cisco:ios_xr:5.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xr:5.1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xr:5.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xr:5.2.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



