Cisco IOS 15.5S and IOS XE allow remote authenticated users to cause a denial of service (device crash) by leveraging knowledge of the RADIUS secret and sending crafted RADIUS packets, aka Bug ID CSCur21348.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0709
Reference (s):
- CISCO:20150428 Cisco IOS Software and Cisco IOS XE Software Crafted RADIUS Packet Denial of Service Vulnerability
- URL: http://tools.cisco.com/security/center/viewAlert.x?alertId=38544
- SECTRACK:1032211
- URL: http://www.securitytracker.com/id/1032211