First published: Fri Sep 27 2013(Updated: )
Cisco IOS 15.0 through 15.3 and IOS XE 3.2 through 3.8, when a VRF interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via crafted UDP RSVP packets, aka Bug ID CSCuf17023.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =15.0 | |
Cisco IOS | =15.1 | |
Cisco IOS | =15.2 | |
Cisco IOS | =15.3 | |
Cisco IOS XE | =3.2.00.xo.15.0\(2\)xo | |
Cisco IOS XE | =3.2.0s | |
Cisco IOS XE | =3.2.0sg | |
Cisco IOS XE | =3.2.0xo | |
Cisco IOS XE | =3.2.1s | |
Cisco IOS XE | =3.2.1sg | |
Cisco IOS XE | =3.2.2s | |
Cisco IOS XE | =3.2.2sg | |
Cisco IOS XE | =3.2.3sg | |
Cisco IOS XE | =3.2.4sg | |
Cisco IOS XE | =3.3.0s | |
Cisco IOS XE | =3.3.0sg | |
Cisco IOS XE | =3.3.1s | |
Cisco IOS XE | =3.3.1sg | |
Cisco IOS XE | =3.3.2s | |
Cisco IOS XE | =3.3.3s | |
Cisco IOS XE | =3.4.0as | |
Cisco IOS XE | =3.4.0s | |
Cisco IOS XE | =3.4.1s | |
Cisco IOS XE | =3.4.2s | |
Cisco IOS XE | =3.4.3s | |
Cisco IOS XE | =3.4.4s | |
Cisco IOS XE | =3.4.5s | |
Cisco IOS XE | =3.4.xs | |
Cisco IOS XE | =3.5.0s | |
Cisco IOS XE | =3.5.1s | |
Cisco IOS XE | =3.5.2s | |
Cisco IOS XE | =3.5.xs | |
Cisco IOS XE | =3.6.0s | |
Cisco IOS XE | =3.6.1s | |
Cisco IOS XE | =3.6.2s | |
Cisco IOS XE | =3.7.0s | |
Cisco IOS XE | =3.7.1s | |
Cisco IOS XE | =3.8.0s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5478 has a high severity rating due to its potential to cause a denial of service on affected devices.
To fix CVE-2013-5478, upgrade your Cisco IOS or IOS XE software to a version that addresses this vulnerability.
CVE-2013-5478 affects Cisco IOS versions 15.0 through 15.3 and Cisco IOS XE versions 3.2 through 3.8.
The impact of CVE-2013-5478 can lead to a denial of service, potentially disrupting network services by wedging the interface queue.
Yes, CVE-2013-5478 allows remote attackers to exploit the vulnerability through crafted UDP RSVP packets.