CVE-2013-6982: Input Validation
The BGP implementation in Cisco NX-OS 6.2(2a) and earlier does not properly handle the interaction of UPDATE messages with IPv6, VPNv4, and VPNv6 labeled unicast-address families, which allows remote attackers to cause a denial of service (peer reset) via a crafted message, aka Bug ID CSCuj03174.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco NX-OSto a version that resolves this vulnerability.Fixed in 6.2(2a)Patch Bug ID CSCuj03174
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6982?
CVE-2013-6982 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2013-6982?
To fix CVE-2013-6982, update your Cisco NX-OS to the latest version that addresses this vulnerability.
What versions of Cisco NX-OS are affected by CVE-2013-6982?
The affected versions include Cisco NX-OS 6.2(2a) and earlier releases.
What kind of attack does CVE-2013-6982 allow?
CVE-2013-6982 allows remote attackers to execute a denial-of-service attack through crafted BGP UPDATE messages.
Is there a workaround for CVE-2013-6982?
There are no known effective workarounds for CVE-2013-6982, so the recommendation is to apply the patch.