First published: Sat Nov 16 2013(Updated: )
The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | <=15.3 | |
Cisco IOS | =15.0 | |
Cisco IOS | =15.0\(1\)se | |
Cisco IOS | =15.1 | |
Cisco IOS | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6686 has been classified as a denial of service vulnerability.
To fix CVE-2013-6686, upgrade your Cisco IOS to version 15.3(1)T3 or later.
Remote authenticated users of Cisco IOS versions 15.3(1)T2 and earlier are affected by CVE-2013-6686.
CVE-2013-6686 enables an attacker to cause a denial of service by sending crafted DTLS packets.
Monitor all releases of Cisco IOS prior to 15.3(1)T3, including 15.0, 15.1, and 15.2 for CVE-2013-6686.