CVE-2015-4205: Cisco IOS XR

Medium severity, CVSS 5.7. EPSS: 0.9% chance of exploitation in the next 30 days.

Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x flow-control PAUSE frames on the local network, aka Bug ID CSCut19959.

Affected products

  • Cisco IOS XR: version 5.3.1 only

Published 2015-06-23. Last modified 2026-06-17.