CVE-2013-5479: Input Validation
Published Sep 27, 2013
·Updated
The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka Bug ID CSCtn53730.
Affected Software
5 affected components
Cisco IOS=12.2
Cisco IOS=15.0
Cisco IOS=15.1
Cisco IOS=15.2
Cisco IOS=15.3
Event History
Sep 27, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5479?
CVE-2013-5479 has a high severity rating as it can lead to a denial of service condition.
2
How do I fix CVE-2013-5479?
To mitigate CVE-2013-5479, upgrade to a fixed version of Cisco IOS or disable NAT if possible.
3
Which Cisco IOS versions are affected by CVE-2013-5479?
CVE-2013-5479 affects Cisco IOS versions 12.2, 15.0, 15.1, 15.2, and 15.3.
4
Can CVE-2013-5479 be exploited remotely?
Yes, CVE-2013-5479 can be exploited remotely via a specially crafted IPv4 DNS TCP stream.
5
What impact does CVE-2013-5479 have on affected systems?
Exploitation of CVE-2013-5479 can cause the affected Cisco devices to reload, resulting in service interruptions.