CVE-2013-5480: Input Validation
Published Sep 27, 2013
·Updated
The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka Bug ID CSCuf28733.
Affected Software
5 affected components
Cisco IOS=12.2
Cisco IOS=15.0
Cisco IOS=15.1
Cisco IOS=15.2
Cisco IOS=15.3
Event History
Sep 27, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5480?
CVE-2013-5480 is classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2013-5480?
To fix CVE-2013-5480, upgrade to a non-vulnerable version of Cisco IOS that is later than 15.3.
3
What types of systems are affected by CVE-2013-5480?
CVE-2013-5480 affects Cisco IOS versions 12.2, 15.0, 15.1, 15.2, and 15.3 when NAT is used.
4
What are the attack vectors for CVE-2013-5480?
The attack vector for CVE-2013-5480 is a crafted IPv4 DNS TCP stream sent to a vulnerable Cisco device.
5
Can CVE-2013-5480 be exploited remotely?
Yes, CVE-2013-5480 can be exploited remotely, allowing attackers to trigger a device reload.