First published: Thu Oct 31 2013(Updated: )
The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via large TCP packets that are processed by the (1) NAT or (2) ALG component, aka Bug ID CSCud72509.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =3.7.0s | |
Cisco IOS XE Software | =3.7.1s | |
Cisco IOS XE Software | =3.7.2s | |
Cisco IOS XE Software | =3.8.0s | |
Cisco ASR 1001 | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1023 Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5546 has a severity rating of High due to the potential for remote denial of service attacks.
To fix CVE-2013-5546, upgrade your Cisco IOS XE software to version 3.7.3S or later, or 3.8.1S or later.
CVE-2013-5546 affects Cisco ASR 1000 series devices running versions 3.7.0S through 3.8.0S.
CVE-2013-5546 allows attackers to cause a denial of service by sending large TCP packets that overwhelm the device.
CVE-2013-5546 was disclosed on October 30, 2013.