CVE-2013-1142
published 2013-03-28CVE-2013-1142: Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 allows remote attackers to cause a denial of service (memory…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.06%
61.0th percentile
Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 allows remote attackers to cause a denial of service (memory consumption) via IPv4 packets, aka Bug IDs CSCtg47129 and CSCtz96745.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | 12.2 – 12.4 | — |
| cisco | ios | 15.0 – 15.2 | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Network Address Translation Vulnerability
vendor_cisco·2013-03-27·CVSS 7.8
CVE-2013-1142 [HIGH] Cisco IOS Software Network Address Translation Vulnerability
Cisco IOS Software Network Address Translation Vulnerability
The Cisco IOS Software implementation of the virtual routing and forwarding (VRF) aware network address translation (NAT) feature contains a vulnerability when translating IP packets that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-nat
Note: The March 27, 2013, Cisco IOS Software Security Advisory bundled publication includes seven Cisco Security Advisories. All advisories address vulnerabilities in Cisco
Cisco
Cisco IOS Software Network Address Translation Denial of Service Vulnerability
vendor_cisco·2013-03-27·CVSS 7.8
CVE-2013-1142 [HIGH] CWE-399 Cisco IOS Software Network Address Translation Denial of Service Vulnerability
Cisco IOS Software Network Address Translation Denial of Service Vulnerability
Cisco IOS Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a reload of a vulnerable device.
The vulnerability is due to improper translation of valid Session Initiation Protocol (SIP) packets across a Network Address Translation (NAT) boundary. An attacker could exploit this vulnerability by repeatedly sending certain SIP packets. An exploit could allow the attacker to cause an extended denial of service (DoS) condition.
Cisco confirmed the vulnerability in a security advisory and released software updates.
The attacker may need access to trusted, internal network resources. This access requirement reduces the exposure of this vulnerability.
Cisco indicates th
Cisco
Cisco IOS Software Network Address Translation Vulnerability
vendor_cisco
CVE-2013-1142 Cisco IOS Software Network Address Translation Vulnerability
CVE-2013-1142: Cisco IOS Software Network Address Translation Vulnerability
The Cisco IOS Software implementation of the virtual routing and forwarding (VRF) aware network address translation (NAT) feature contains a vulnerability when translating IP packets that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability.
Bug IDs: CSCtg47129, CSCtz96745, CSCtg47129, CSCtz96745, CSCta48550
GHSA
GHSA-hh95-5fxw-r47q: Race condition in the VRF-aware NAT feature in Cisco IOS 12
ghsa_unreviewed·2022-05-13
CVE-2013-1142 [HIGH] CWE-362 GHSA-hh95-5fxw-r47q: Race condition in the VRF-aware NAT feature in Cisco IOS 12
Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 allows remote attackers to cause a denial of service (memory consumption) via IPv4 packets, aka Bug IDs CSCtg47129 and CSCtz96745.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-nathttp://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1142http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-nathttp://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1142
2013-03-28
Published