First published: Fri Nov 22 2013(Updated: )
The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Cisco IOS | <=15.3\(3\)s | |
Puppet Cisco IOS | =15.3\(2\)s | |
Puppet Cisco IOS | =15.3s | |
Cisco 7600 Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6693 has a medium severity rating due to the potential for denial of service attacks on affected Cisco devices.
To mitigate CVE-2013-6693, upgrade to Cisco IOS version 15.3(4)S or later.
CVE-2013-6693 primarily affects Cisco IOS 15.3(3)S and earlier versions running on Cisco 7600 routers.
CVE-2013-6693 allows remote attackers to cause a denial of service by establishing numerous multicast flows.
There are no specific workarounds for CVE-2013-6693; the recommended action is to apply the appropriate software upgrade.