CVE-2013-5547: Input Validation
Published Oct 31, 2013
·Updated
Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCuf08269.
Affected Software
8 affected components
Cisco IOS XE=3.9.0s
Cisco IOS XE=3.9.1s
Cisco Asr 1001
Cisco Asr 1002
Cisco Asr 1002-x
Cisco Asr 1004
Cisco Asr 1006
Cisco Asr 1023 Router
Event History
Oct 31, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5547?
CVE-2013-5547 has a high severity rating due to its potential to cause a denial of service through device reload.
2
How do I fix CVE-2013-5547?
To fix CVE-2013-5547, upgrade your Cisco IOS XE device to version 3.9.2S or later.
3
What devices are affected by CVE-2013-5547?
CVE-2013-5547 affects various Cisco ASR 1000 series devices running IOS XE versions 3.9.0S and 3.9.1S.
4
What type of attack does CVE-2013-5547 enable?
CVE-2013-5547 enables remote attackers to cause a denial of service by sending malformed EoGRE packets.
5
What is the impact of CVE-2013-5547 on network operations?
The impact of CVE-2013-5547 can lead to unexpected device reloads, disrupting network operations.