CVE-2013-2779: Input Validation
Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 MVPN (aka MVPNv6) packets, aka Bug ID CSCub34945, a different vulnerability than CVE-2013-1164.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2779?
CVE-2013-2779 is classified as a high-severity vulnerability that can lead to denial of service on affected Cisco devices.
How do I fix CVE-2013-2779?
To mitigate CVE-2013-2779, update your Cisco IOS XE software to version 3.4.5S or later, or 3.7.1S or later.
Which devices are affected by CVE-2013-2779?
CVE-2013-2779 affects Cisco 1000 series Aggregation Services Routers (ASR) running specific vulnerable versions of Cisco IOS XE.
What impact does CVE-2013-2779 have on systems?
CVE-2013-2779 allows remote attackers to cause a denial of service by triggering a card reload in affected devices.
How can I check if my Cisco device is vulnerable to CVE-2013-2779?
You can check the version of the Cisco IOS XE running on your device against the affected versions listed in the CVE report.