CVE-2015-6432: Cisco IOS XR

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PCEs) for OSPF LSA opaque area updates, which allows remote attackers to cause a denial of service (device reload) via a crafted update, aka Bug ID CSCuw83486.

Affected products

  • Cisco IOS XR: version 4.2.0 only; version 4.3.0 only; version 5.0.0 only; version 5.1.0 only; version 5.2.0 only; version 5.2.2 only; …

Published 2016-01-05. Last modified 2026-06-17.