The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a series of packets that are considered oversized and trigger improper fragmentation handling, aka Bug IDs CSCup37676 and CSCup30335.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0710
Reference (s):
- CISCO:20150428 Cisco IOS XE Software OTV Processing Code Denial of Service Vulnerability
- URL: http://tools.cisco.com/security/center/viewAlert.x?alertId=38549
- SECTRACK:1032212
- URL: http://www.securitytracker.com/id/1032212

