First published: Thu Apr 11 2013(Updated: )
Cisco IOS XE 3.2 through 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR), when VRF-aware NAT and SIP ALG are enabled, allows remote attackers to cause a denial of service (card reload) by sending many SIP packets, aka Bug ID CSCuc65609.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco ASR 1001 | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1023 Router | ||
Cisco IOS XE | =3.2.0s | |
Cisco IOS XE | =3.2.1s | |
Cisco IOS XE | =3.2.2s | |
Cisco IOS XE | =3.3.0s | |
Cisco IOS XE | =3.3.1s | |
Cisco IOS XE | =3.3.2s | |
Cisco IOS XE | =3.4.0as | |
Cisco IOS XE | =3.4.0s | |
Cisco IOS XE | =3.4.1s | |
Cisco IOS XE | =3.4.2s | |
Cisco IOS XE | =3.4.3s | |
Cisco IOS XE | =3.4.4s | |
Cisco IOS XE | =3.7.0s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1166 has a severity rating that indicates a moderate risk of denial of service due to the potential for a card reload.
To fix CVE-2013-1166, upgrade the affected Cisco IOS XE software to version 3.4.5S or later, or 3.7.1S or later.
CVE-2013-1166 affects Cisco ASR 1001, ASR 1002, ASR 1004, ASR 1006, and ASR 1023 routers running specific versions of Cisco IOS XE.
CVE-2013-1166 allows remote attackers to execute a denial of service attack by flooding the system with SIP packets.
As a workaround for CVE-2013-1166, consider disabling VRF-aware NAT or the SIP ALG feature if they are not required.