First published: Thu Oct 31 2013(Updated: )
The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =3.9.0s | |
Cisco IOS XE Software | =3.9.1s | |
Cisco ASR 1001 | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1023 Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-5545 is classified as high due to its potential to cause a denial of service.
To fix CVE-2013-5545, upgrade your Cisco IOS XE to version 3.9.2S or later.
CVE-2013-5545 affects various Cisco ASR 1000 devices running IOS XE versions 3.9.0S and 3.9.1S.
CVE-2013-5545 exploits the PPTP Application Layer Gateway (ALG) implementation to cause denial of service.
There is no specific workaround for CVE-2013-5545; upgrading to the fixed version is recommended for protection.