CVE-2015-0649: Cisco IOS

High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.

Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.

Affected products

  • Cisco IOS: version 12.2(33)ird1 only; version 12.2(33)ire3 only; version 12.2(33)sxi4b only; version 12.2(44)sq1 only; version 12.2(52)se only; version 12.2(52)se1 only; …

Published 2015-03-26. Last modified 2026-06-17.