The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and packet loss) via malformed HTTP packets, aka Bug ID CSCud14217.
2015-05-01T10:59:01.153
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | staros | 12.0 | Yes |
Operating System | cisco | staros | 12.2\(300\) | Yes |
Operating System | cisco | staros | 14.0 | Yes |
Operating System | cisco | staros | 14.0\(600\) | Yes |
Hardware | cisco | asr_5000 | - | No |
Hardware | cisco | asr_5500 | - | No |
Hardware | cisco | asr_5700 | - | No |