CVE-2013-1147: Buffer Overflow
The Protocol Translation (PT) functionality in Cisco IOS 12.3 through 12.4 and 15.0 through 15.3, when one-step port-23 translation or a Telnet-to-PAD ruleset is configured, does not properly validate TCP connection information, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a PT resource, aka Bug ID CSCtz35999.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1147?
CVE-2013-1147 is classified as a denial of service vulnerability that affects multiple versions of Cisco IOS.
How do I fix CVE-2013-1147?
To mitigate CVE-2013-1147, users should upgrade to a supported version of Cisco IOS that has addressed the vulnerability.
Which Cisco IOS versions are affected by CVE-2013-1147?
CVE-2013-1147 affects Cisco IOS versions 12.3, 12.4, 15.0, 15.1, 15.2, and 15.3.
Can CVE-2013-1147 be exploited remotely?
Yes, CVE-2013-1147 can be exploited remotely, allowing attackers to cause a denial of service.
What functionalities are impacted by CVE-2013-1147?
CVE-2013-1147 affects the Protocol Translation functionality within affected Cisco IOS versions, particularly when specific Telnet configurations are used.