CVE-2013-5549: High severity Cisco IOS XR vulnerability
Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCuh30380.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5549?
CVE-2013-5549 has a severity rating that indicates a potential for denial of service vulnerabilities affecting Cisco IOS XR.
How do I fix CVE-2013-5549?
To fix CVE-2013-5549, update your Cisco IOS XR software to a version that is not vulnerable, starting from 4.2.1 or later.
Which Cisco IOS XR versions are affected by CVE-2013-5549?
CVE-2013-5549 affects Cisco IOS XR versions from 3.8.1 to 4.2.0.
Can CVE-2013-5549 affect IPv4 and IPv6 traffic?
Yes, CVE-2013-5549 can affect both IPv4 and IPv6 traffic causing potential transmission outages.
What kind of attack does CVE-2013-5549 allow?
CVE-2013-5549 allows remote attackers to launch a denial-of-service attack against affected Cisco IOS XR devices.