CVE-2013-5545: Input Validation
Published Oct 31, 2013
·Updated
The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936.
Affected Software
8 affected components
Cisco IOS XE=3.9.0s
Cisco IOS XE=3.9.1s
Cisco Asr 1001
Cisco Asr 1002
Cisco Asr 1002-x
Cisco Asr 1004
Cisco Asr 1006
Cisco Asr 1023 Router
Event History
Oct 31, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5545?
The severity of CVE-2013-5545 is classified as high due to its potential to cause a denial of service.
2
How do I fix CVE-2013-5545?
To fix CVE-2013-5545, upgrade your Cisco IOS XE to version 3.9.2S or later.
3
Which Cisco devices are affected by CVE-2013-5545?
CVE-2013-5545 affects various Cisco ASR 1000 devices running IOS XE versions 3.9.0S and 3.9.1S.
4
What type of attack does CVE-2013-5545 exploit?
CVE-2013-5545 exploits the PPTP Application Layer Gateway (ALG) implementation to cause denial of service.
5
Is there a workaround for CVE-2013-5545 if I cannot upgrade?
There is no specific workaround for CVE-2013-5545; upgrading to the fixed version is recommended for protection.