CVE-2013-6706: Input Validation
Published Nov 29, 2013
·Updated
The Cisco Express Forwarding processing module in Cisco IOS XE allows remote attackers to cause a denial of service (device reload) via crafted MPLS packets that are not properly handled during IP header validation, aka Bug ID CSCuj23992.
Affected Software
1 affected component
Cisco IOS XE
Event History
Nov 29, 2013
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:33 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6706?
CVE-2013-6706 has a medium severity rating of 5.4.
2
What is the impact of CVE-2013-6706?
CVE-2013-6706 allows remote attackers to cause a denial of service by triggering a device reload.
3
How do I fix CVE-2013-6706?
To mitigate CVE-2013-6706, update to the latest version of Cisco IOS XE that addresses this vulnerability.
4
What types of attacks does CVE-2013-6706 defend against?
CVE-2013-6706 is specifically vulnerable to crafted MPLS packets that exploit improper IP header validation.
5
Which systems are affected by CVE-2013-6706?
CVE-2013-6706 affects devices running Cisco IOS XE that utilize the Cisco Express Forwarding processing module.