CVE-2013-6694: Input Validation
Published Nov 22, 2013
·Updated
The IPSec implementation in Cisco IOS allows remote attackers to cause a denial of service (MTU change and tunnel-session drop) via crafted ICMP packets, aka Bug ID CSCul29918.
Affected Software
1 affected component
Cisco IOS
Event History
Nov 22, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6694?
CVE-2013-6694 is classified with a medium severity score of 4.3.
2
What kind of attack does CVE-2013-6694 enable?
CVE-2013-6694 allows attackers to cause a denial of service by sending crafted ICMP packets.
3
How does CVE-2013-6694 affect Cisco IOS?
CVE-2013-6694 impacts the IPSec implementation in Cisco IOS, leading to potential MTU changes and tunnel-session drops.
4
What is the impact of CVE-2013-6694 on system availability?
CVE-2013-6694 can result in a denial of service, affecting the availability of the device due to session drops.
5
How can I mitigate the risks associated with CVE-2013-6694?
To mitigate CVE-2013-6694, it's recommended to apply patches provided by Cisco for vulnerable versions of IOS.