CVE-2015-4243: Cisco IOS XE

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty94202.

Affected products

  • Cisco IOS XE: version 3.5.0s only

Published 2015-07-08. Last modified 2026-06-17.