CVE-2015-0635: Cisco IOS

High severity, CVSS 9.0. EPSS: 2.1% chance of exploitation in the next 30 days.

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device and node access restrictions or cause a denial of service (disrupted domain access), via crafted AN messages, aka Bug ID CSCup62191.

Affected products

  • Cisco IOS: version 12.2(33)ird1 only; version 12.2(33)ire3 only; version 12.2(33)sxi4b only; version 12.2(44)sq1 only; version 12.4(25e)jam1 only; version 12.4(25e)jap1m only; …
  • Cisco IOS XE: version 3.10s.0 only; version 3.10s.1 only; version 3.10s.2 only; version 3.10s.3 only; version 3.10s.4 only; version 3.10s.5 only; …

Published 2015-03-26. Last modified 2026-06-17.