CVE-2013-5481: Input Validation
Published Sep 27, 2013
·Updated
The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted TCP port-1723 packets, aka Bug ID CSCtq14817.
Affected Software
5 affected components
Cisco IOS=12.2
Cisco IOS=15.0
Cisco IOS=15.1
Cisco IOS=15.2
Cisco IOS=15.3
Event History
Sep 27, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5481?
CVE-2013-5481 is classified as a high severity vulnerability that can lead to denial of service attacks.
2
How do I fix CVE-2013-5481?
To fix CVE-2013-5481, you should update the Cisco IOS software to the latest version that addresses this vulnerability.
3
What specific devices are affected by CVE-2013-5481?
CVE-2013-5481 affects Cisco IOS versions 12.2, 15.0, 15.1, 15.2, and 15.3 when NAT is used.
4
Can CVE-2013-5481 be exploited remotely?
Yes, CVE-2013-5481 can be exploited remotely by sending crafted TCP port-1723 packets.
5
What impact does CVE-2013-5481 have on systems?
The impact of CVE-2013-5481 includes potential device reloading, causing a denial of service.