Vulnerabilities > Cisco > ASR 1002 X

DATE CVE VULNERABILITY TITLE RISK
2015-04-04 CVE-2015-0688 Resource Management Errors vulnerability in Cisco IOS XE 13.10.2S
Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.
network
cisco CWE-399
7.1
2014-05-25 CVE-2014-3284 Improper Input Validation vulnerability in Cisco products
Cisco IOS XE on ASR1000 devices, when PPPoE termination is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed PPPoE packet, aka Bug ID CSCuo55180.
low complexity
cisco CWE-20
6.1
2014-04-29 CVE-2014-2183 Improper Input Validation vulnerability in Cisco products
The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
network
cisco CWE-20
6.3
2014-04-24 CVE-2012-5723 Improper Input Validation vulnerability in Cisco products
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.
low complexity
cisco CWE-20
6.1
2014-04-23 CVE-2012-5017 Improper Input Validation vulnerability in Cisco products
Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.
network
low complexity
cisco CWE-20
6.8
2014-04-23 CVE-2012-1366 Improper Input Validation vulnerability in Cisco products
Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.
low complexity
cisco CWE-20
6.1
2013-10-31 CVE-2013-5547 Improper Input Validation vulnerability in Cisco products
Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCuf08269.
network
low complexity
cisco CWE-20
7.8
2013-10-31 CVE-2013-5546 Improper Input Validation vulnerability in Cisco products
The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via large TCP packets that are processed by the (1) NAT or (2) ALG component, aka Bug ID CSCud72509.
network
low complexity
cisco CWE-20
7.8
2013-10-31 CVE-2013-5545 Improper Input Validation vulnerability in Cisco products
The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936.
network
low complexity
cisco CWE-20
7.8
2013-10-31 CVE-2013-5543 Improper Input Validation vulnerability in Cisco products
Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via malformed ICMP error packets associated with a (1) TCP or (2) UDP session that is under inspection by the Zone-Based Firewall (ZBFW) component, aka Bug ID CSCtt26470.
network
low complexity
cisco CWE-20
7.8