First published: Thu Oct 31 2013(Updated: )
Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via malformed ICMP error packets associated with a (1) TCP or (2) UDP session that is under inspection by the Zone-Based Firewall (ZBFW) component, aka Bug ID CSCtt26470.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =3.4.0as | |
Cisco IOS XE Software | =3.4.0s | |
Cisco IOS XE Software | =3.4.1s | |
Cisco ASR 1001 | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1023 Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5543 has a severity rating that can lead to a denial of service affecting Cisco ASR devices.
To fix CVE-2013-5543, update your Cisco IOS XE software to version 3.4.2S or 3.5.1S or later.
CVE-2013-5543 affects various ASR 1000 series routers running earlier versions of Cisco IOS XE.
CVE-2013-5543 enables remote attackers to cause a denial of service by sending malformed ICMP error packets.
There is no mitigation for CVE-2013-5543 other than upgrading to the patched Cisco IOS XE versions.