CVE-2013-1166: Input Validation
Cisco IOS XE 3.2 through 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR), when VRF-aware NAT and SIP ALG are enabled, allows remote attackers to cause a denial of service (card reload) by sending many SIP packets, aka Bug ID CSCuc65609.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1166?
CVE-2013-1166 has a severity rating that indicates a moderate risk of denial of service due to the potential for a card reload.
How do I fix CVE-2013-1166?
To fix CVE-2013-1166, upgrade the affected Cisco IOS XE software to version 3.4.5S or later, or 3.7.1S or later.
What devices are affected by CVE-2013-1166?
CVE-2013-1166 affects Cisco ASR 1001, ASR 1002, ASR 1004, ASR 1006, and ASR 1023 routers running specific versions of Cisco IOS XE.
What type of attack does CVE-2013-1166 allow for?
CVE-2013-1166 allows remote attackers to execute a denial of service attack by flooding the system with SIP packets.
Is there a workaround for CVE-2013-1166?
As a workaround for CVE-2013-1166, consider disabling VRF-aware NAT or the SIP ALG feature if they are not required.