ID

VAR-201503-0172


CVE

CVE-2015-0669


TITLE

Cisco IOS of Autonomic Networking Infrastructure Vulnerability in changing configuration settings

Trust: 0.8

sources: JVNDB: JVNDB-2015-001899

DESCRIPTION

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15.4S and 15.4(3)S allows remote attackers to modify configuration settings or cause a denial of service (partial service outage) by sending crafted Autonomic Networking (AN) messages on an intranet network, aka Bug ID CSCup62167. Cisco IOS is an operating system developed by Cisco Systems for its network devices. An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks. This issue is tracked by Cisco Bug ID CSCup62167

Trust: 2.52

sources: NVD: CVE-2015-0669 // JVNDB: JVNDB-2015-001899 // CNVD: CNVD-2015-01924 // BID: 73245 // VULHUB: VHN-78615

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-01924

AFFECTED PRODUCTS

vendor:ciscomodel:iosscope:eqversion:15.4s

Trust: 2.4

vendor:ciscomodel:iosscope:eqversion:15.4\(3\)s

Trust: 1.6

vendor:ciscomodel:ios 15.4sscope: - version: -

Trust: 0.9

vendor:ciscomodel:ios 15.4 sscope: - version: -

Trust: 0.9

vendor:ciscomodel:iosscope:eqversion:15.4(3)s

Trust: 0.8

sources: CNVD: CNVD-2015-01924 // BID: 73245 // JVNDB: JVNDB-2015-001899 // CNNVD: CNNVD-201503-415 // NVD: CVE-2015-0669

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0669
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-0669
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-01924
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201503-415
value: MEDIUM

Trust: 0.6

VULHUB: VHN-78615
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-0669
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-01924
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-78615
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-01924 // VULHUB: VHN-78615 // JVNDB: JVNDB-2015-001899 // CNNVD: CNNVD-201503-415 // NVD: CVE-2015-0669

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-78615 // JVNDB: JVNDB-2015-001899 // NVD: CVE-2015-0669

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201503-415

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201503-415

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001899

PATCH

title:37935url:http://tools.cisco.com/security/center/viewAlert.x?alertId=37935

Trust: 0.8

title:Patch for Cisco IOS Autonomic Networking Infrastructure Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/56591

Trust: 0.6

sources: CNVD: CNVD-2015-01924 // JVNDB: JVNDB-2015-001899

EXTERNAL IDS

db:NVDid:CVE-2015-0669

Trust: 3.4

db:SECTRACKid:1031967

Trust: 1.1

db:BIDid:73245

Trust: 1.0

db:JVNDBid:JVNDB-2015-001899

Trust: 0.8

db:CNNVDid:CNNVD-201503-415

Trust: 0.7

db:CNVDid:CNVD-2015-01924

Trust: 0.6

db:VULHUBid:VHN-78615

Trust: 0.1

sources: CNVD: CNVD-2015-01924 // VULHUB: VHN-78615 // BID: 73245 // JVNDB: JVNDB-2015-001899 // CNNVD: CNNVD-201503-415 // NVD: CVE-2015-0669

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=37935

Trust: 2.6

url:http://www.securitytracker.com/id/1031967

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0669

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0669

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/public/sw-center/sw-ios.shtml

Trust: 0.3

sources: CNVD: CNVD-2015-01924 // VULHUB: VHN-78615 // BID: 73245 // JVNDB: JVNDB-2015-001899 // CNNVD: CNNVD-201503-415 // NVD: CVE-2015-0669

CREDITS

Cisco

Trust: 0.3

sources: BID: 73245

SOURCES

db:CNVDid:CNVD-2015-01924
db:VULHUBid:VHN-78615
db:BIDid:73245
db:JVNDBid:JVNDB-2015-001899
db:CNNVDid:CNNVD-201503-415
db:NVDid:CVE-2015-0669

LAST UPDATE DATE

2025-04-13T23:36:28.575000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-01924date:2015-03-24T00:00:00
db:VULHUBid:VHN-78615date:2015-10-01T00:00:00
db:BIDid:73245date:2015-03-19T00:00:00
db:JVNDBid:JVNDB-2015-001899date:2015-03-24T00:00:00
db:CNNVDid:CNNVD-201503-415date:2015-03-27T00:00:00
db:NVDid:CVE-2015-0669date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-01924date:2015-03-24T00:00:00
db:VULHUBid:VHN-78615date:2015-03-21T00:00:00
db:BIDid:73245date:2015-03-19T00:00:00
db:JVNDBid:JVNDB-2015-001899date:2015-03-24T00:00:00
db:CNNVDid:CNNVD-201503-415date:2015-03-23T00:00:00
db:NVDid:CVE-2015-0669date:2015-03-21T01:59:00.090