CVE-2013-1146: Buffer Overflow
The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in Smart Install packets, aka Bug ID CSCub55790.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1146?
CVE-2013-1146 has a severity rating of high due to its potential to cause a denial of service by device reload.
How do I fix CVE-2013-1146?
To fix CVE-2013-1146, update your Cisco IOS to a version that is not affected by this vulnerability.
What devices are affected by CVE-2013-1146?
CVE-2013-1146 affects Cisco IOS versions 12.2 and 15.0 through 15.3 on Catalyst switches.
What type of attack does CVE-2013-1146 involve?
CVE-2013-1146 involves a remote denial of service attack through crafted image list parameters in Smart Install packets.
Is there a workaround for CVE-2013-1146?
Yes, disabling the Smart Install service can act as a temporary workaround for CVE-2013-1146.