ID

VAR-201503-0165


CVE

CVE-2015-0661


TITLE

Cisco IOS XR of SNMPv2 Service disruption in implementations (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-001670

DESCRIPTION

The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon reload) via a malformed SNMP packet, aka Bug ID CSCur25858. Cisco IOS XR is a fully modular, distributed network operating system from Cisco's IOS software family. A security vulnerability exists in the Cisco Network IOS XR Simple Network Management Protocol version 2 (SNMPv2) process. Attackers can exploit this issue to cause the snmpd process on the affected device to reload, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCur25858

Trust: 2.52

sources: NVD: CVE-2015-0661 // JVNDB: JVNDB-2015-001670 // CNVD: CNVD-2015-01499 // BID: 72968 // VULHUB: VHN-78607

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-01499

AFFECTED PRODUCTS

vendor:ciscomodel:ios xrscope: - version: -

Trust: 2.0

vendor:ciscomodel:ios xrscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:ios xr softwarescope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2015-01499 // BID: 72968 // JVNDB: JVNDB-2015-001670 // CNNVD: CNNVD-201503-119 // NVD: CVE-2015-0661

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0661
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-0661
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-01499
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201503-119
value: MEDIUM

Trust: 0.6

VULHUB: VHN-78607
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-0661
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-01499
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-78607
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-01499 // VULHUB: VHN-78607 // JVNDB: JVNDB-2015-001670 // CNNVD: CNNVD-201503-119 // NVD: CVE-2015-0661

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-78607 // JVNDB: JVNDB-2015-001670 // NVD: CVE-2015-0661

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201503-119

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201503-119

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001670

PATCH

title:Cisco IOS XR Software Malformed SNMP Packet Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0661

Trust: 0.8

title:Cisco IOS XR SNMPv2 implements a denial of service vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/55937

Trust: 0.6

sources: CNVD: CNVD-2015-01499 // JVNDB: JVNDB-2015-001670

EXTERNAL IDS

db:NVDid:CVE-2015-0661

Trust: 3.4

db:SECTRACKid:1031843

Trust: 1.1

db:BIDid:72968

Trust: 1.0

db:JVNDBid:JVNDB-2015-001670

Trust: 0.8

db:CNNVDid:CNNVD-201503-119

Trust: 0.7

db:CNVDid:CNVD-2015-01499

Trust: 0.6

db:VULHUBid:VHN-78607

Trust: 0.1

sources: CNVD: CNVD-2015-01499 // VULHUB: VHN-78607 // BID: 72968 // JVNDB: JVNDB-2015-001670 // CNNVD: CNNVD-201503-119 // NVD: CVE-2015-0661

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2015-0661

Trust: 2.6

url:http://www.securitytracker.com/id/1031843

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0661

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0661

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps5845/index.html

Trust: 0.3

sources: CNVD: CNVD-2015-01499 // VULHUB: VHN-78607 // BID: 72968 // JVNDB: JVNDB-2015-001670 // CNNVD: CNNVD-201503-119 // NVD: CVE-2015-0661

CREDITS

Cisco

Trust: 0.3

sources: BID: 72968

SOURCES

db:CNVDid:CNVD-2015-01499
db:VULHUBid:VHN-78607
db:BIDid:72968
db:JVNDBid:JVNDB-2015-001670
db:CNNVDid:CNNVD-201503-119
db:NVDid:CVE-2015-0661

LAST UPDATE DATE

2024-11-23T22:45:58.212000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-01499date:2015-03-09T00:00:00
db:VULHUBid:VHN-78607date:2015-11-02T00:00:00
db:BIDid:72968date:2015-03-05T00:00:00
db:JVNDBid:JVNDB-2015-001670date:2015-03-09T00:00:00
db:CNNVDid:CNNVD-201503-119date:2015-03-06T00:00:00
db:NVDid:CVE-2015-0661date:2024-11-21T02:23:29.517

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-01499date:2015-03-09T00:00:00
db:VULHUBid:VHN-78607date:2015-03-06T00:00:00
db:BIDid:72968date:2015-03-05T00:00:00
db:JVNDBid:JVNDB-2015-001670date:2015-03-09T00:00:00
db:CNNVDid:CNNVD-201503-119date:2015-03-06T00:00:00
db:NVDid:CVE-2015-0661date:2015-03-06T03:00:16.110