Vulnerabilities > Cisco > Staros

DATE CVE VULNERABILITY TITLE RISK
2017-07-04 CVE-2017-3865 Remote Denial of Service vulnerability in Cisco Staros 21.0.0/21.0M0.64246/21.0M0.64702
A vulnerability in the IPsec component of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from establishing, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
5.0
2015-05-01 CVE-2015-0712 Resource Management Errors vulnerability in Cisco Staros
The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and packet loss) via malformed HTTP packets, aka Bug ID CSCud14217.
network
low complexity
cisco CWE-399
5.0
2015-04-29 CVE-2015-0711 Resource Management Errors vulnerability in Cisco Staros 18.1.0.59776
The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and call-processing outage) via malformed PM packets, aka Bug ID CSCut94711.
network
low complexity
cisco CWE-399
5.0
2013-08-05 CVE-2013-0149 Remote Security Bypass vulnerability in Cisco IOS and IOS XE
The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a (1) unicast or (2) multicast packet, aka Bug IDs CSCug34485, CSCug34469, CSCug39762, CSCug63304, and CSCug39795.
network
cisco
5.8