CVE-2015-6278 Information

Description

The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2 15.0 15.1 15.2 15.3 15.4 and 15.5 and IOS XE 3.2SE 3.3SE 3.3XO 3.4SG 3.5E and 3.6E before 3.6.3E; 3.7E before 3.7.2E; 3.9S and 3.10S before 3.10.6S; 3.11S before 3.11.4S; 3.12S and 3.13S before 3.13.3S; and 3.14S before 3.14.2S does not properly implement the Control Plane Protection (aka CPPr) feature which allows remote attackers to cause a denial of service (device reload) via a flood of ND packets aka Bug ID CSCus19794.

Reference

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150923-fhs http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150923-fhs/cvrf/cisco-sa-20150923-fhs_cvrf.xml http://www.securitytracker.com/id/1033647

Share on: