Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-4285

EPSS 0.47% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-4285

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports continuously, aka Bug ID CSCur88273.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco ASR9k IOS XR Local Packet Transport Services 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco IOS XR on ASR9k devices是美国思科(Cisco)公司的一套运行于9000系列路由器设备中的操作系统。 Cisco ASR9k设备上的Cisco IOS XR中的Local Packet Transport Services(LPTS)网络栈中存在安全漏洞,该漏洞源于程序没有正确处理流基本项,导致TCP和UDP端口被错误地开启。远程攻击者可通过不间断地向这些端口发送流量利用该漏洞造成拒绝服务(资源消耗)。以下版本受到影响:Cisco IOS XR 5.1.2版本,5.1.3
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-4285

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-4285

登录查看更多情报信息。

Same Patch Batch · n/a · 2015-07-23 · 23 CVEs total

CVE-2015-1280Google Chrome Skia 缓冲区溢出漏洞
CVE-2015-5605Google Chrome V8 拒绝服务漏洞
CVE-2015-1289Google Chrome 拒绝服务漏洞
CVE-2015-1288Google Chrome Spellcheck API 安全漏洞
CVE-2015-1287Google Chrome Blink 安全漏洞
CVE-2015-1286Google Chrome 跨站脚本漏洞
CVE-2015-1285Google Chrome Blink 安全漏洞
CVE-2015-1284Google Chrome Blink 输入验证漏洞
CVE-2015-1283Google Chrome Expat 数字错误漏洞
CVE-2015-1282Google Chrome PDFium 资源管理错误漏洞
CVE-2015-1281Google Chrome Blink 安全漏洞
CVE-2015-4527EMC Avamar Virtual Edition和EMC Avamar Server 目录遍历漏洞
CVE-2015-1279Google Chrome PDFium 数字错误漏洞
CVE-2015-1278Google Chrome 安全漏洞
CVE-2015-1277Google Chrome accessibility 释放后重用漏洞
CVE-2015-1275Google Chrome 跨站脚本漏洞
CVE-2015-1274Google Chrome 任意代码执行漏洞
CVE-2015-1273Google Chrome PDFium OpenJPEG 基于堆的缓冲区溢出漏洞
CVE-2015-1272Google Chrome GPU程序释放后重用漏洞
CVE-2015-1271Google Chrome PDFium 缓冲区溢出漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2015-4285

No comments yet


Leave a comment