CVE-2013-6686: Input Validation
Published Nov 16, 2013
·Updated
The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.
Affected Software
5 affected components
Cisco IOS<=15.3
Cisco IOS=15.0
Cisco IOS=15.0\(1\)se
Cisco IOS=15.1
Cisco IOS=15.2
Event History
Nov 16, 2013
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Nov 18, 2013
Data Sourced
via NVD·03:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6686?
CVE-2013-6686 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2013-6686?
To fix CVE-2013-6686, upgrade your Cisco IOS to version 15.3(1)T3 or later.
3
Who is affected by CVE-2013-6686?
Remote authenticated users of Cisco IOS versions 15.3(1)T2 and earlier are affected by CVE-2013-6686.
4
What kind of attack does CVE-2013-6686 enable?
CVE-2013-6686 enables an attacker to cause a denial of service by sending crafted DTLS packets.
5
What releases of Cisco IOS should be monitored for CVE-2013-6686?
Monitor all releases of Cisco IOS prior to 15.3(1)T3, including 15.0, 15.1, and 15.2 for CVE-2013-6686.