CVE-2013-5543: Input Validation
Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via malformed ICMP error packets associated with a (1) TCP or (2) UDP session that is under inspection by the Zone-Based Firewall (ZBFW) component, aka Bug ID CSCtt26470.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5543?
CVE-2013-5543 has a severity rating that can lead to a denial of service affecting Cisco ASR devices.
How do I fix CVE-2013-5543?
To fix CVE-2013-5543, update your Cisco IOS XE software to version 3.4.2S or 3.5.1S or later.
What devices are affected by CVE-2013-5543?
CVE-2013-5543 affects various ASR 1000 series routers running earlier versions of Cisco IOS XE.
What type of attack does CVE-2013-5543 enable?
CVE-2013-5543 enables remote attackers to cause a denial of service by sending malformed ICMP error packets.
Is there a mitigation for CVE-2013-5543?
There is no mitigation for CVE-2013-5543 other than upgrading to the patched Cisco IOS XE versions.