CVE-2013-0149: Medium severity cisco ios vulnerability
The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a (1) unicast or (2) multicast packet, aka Bug IDs CSCug34485, CSCug34469, CSCug39762, CSCug63304, and CSCug39795.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0149?
CVE-2013-0149 has a CVSS score of 5.0, indicating a medium severity level.
How do I fix CVE-2013-0149?
To fix CVE-2013-0149, upgrade your Cisco software to a version that addresses the vulnerability, specifically versions released after the advisory.
Which versions are affected by CVE-2013-0149?
CVE-2013-0149 affects Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, as well as various versions of IOS-XE, ASA, PIX, FWSM, and NX-OS.
What type of vulnerability is CVE-2013-0149?
CVE-2013-0149 is a security vulnerability in the OSPF implementation that allows attackers to manipulate the Link State Advertisement database.
Can CVE-2013-0149 be exploited remotely?
Yes, CVE-2013-0149 can be exploited remotely by an attacker sending specially crafted OSPF packets.