CVE-2013-5475: Input Validation
Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets that are processed locally by a (1) server or (2) relay agent, aka Bug ID CSCug31561.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5475?
CVE-2013-5475 has a severity rating that indicates a potential denial of service, leading to device reload.
How do I fix CVE-2013-5475?
To address CVE-2013-5475, update your Cisco IOS or IOS XE to a version that includes the patch for this vulnerability.
Which Cisco products are affected by CVE-2013-5475?
CVE-2013-5475 affects Cisco IOS versions 12.2 to 12.4 and 15.0 to 15.3, as well as certain versions of IOS XE.
What kind of attack does CVE-2013-5475 pose?
CVE-2013-5475 allows remote attackers to launch a denial of service attack by sending crafted DHCP packets.
Is there a workaround for CVE-2013-5475?
While the best solution is to install the latest updates, implementing access controls to limit DHCP traffic may help mitigate the effects of CVE-2013-5475.