Race condition in Nextcloud iOS App - CVE-2015-4199

 

Race condition in Nextcloud iOS App - CVE-2015-4199

Published: June 27, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40707
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-4199
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity with many IPv6 CPE devices, aka Bug ID CSCug47366.


Affected software

Nextcloud iOS App

How to mitigate CVE-2015-4199

Install update from vendor's website.


External References

Related Security Bulletins