CVE-2013-1144
published 2013-03-28CVE-2013-1144: Memory leak in the IKEv1 implementation in Cisco IOS 15.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified (1) IPv4 or…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.89%
77.4th percentile
Memory leak in the IKEv1 implementation in Cisco IOS 15.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified (1) IPv4 or (2) IPv6 IKE packets, aka Bug ID CSCth81055.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Internet Key Exchange Vulnerability
vendor_cisco·2013-03-27·CVSS 7.8
CVE-2013-1144 [HIGH] CWE-119 Cisco IOS Software Internet Key Exchange Vulnerability
Cisco IOS Software Internet Key Exchange Vulnerability
The Cisco IOS Software Internet Key Exchange (IKE) feature contains a denial of service (DoS) vulnerability.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-ike
Note: The March 27, 2013, Cisco IOS Software Security Advisory bundled publication includes seven Cisco Security Advisories. All advisories address vulnerabilities in Cisco IOS Software. Each Cisco IOS Software Security Advisory lists the Cisco IOS Software releases that correct the vulnerability or vulnerabilities detailed in the advisory as well
Cisco
Cisco IOS Software Internet Key Exchange Vulnerability
vendor_cisco
CVE-2013-1144 Cisco IOS Software Internet Key Exchange Vulnerability
CVE-2013-1144: Cisco IOS Software Internet Key Exchange Vulnerability
The Cisco IOS Software Internet Key Exchange (IKE) feature contains a denial of service (DoS) vulnerability. Cisco has released software updates that address this vulnerability.
CWE: CWE-119, CWE-119
Bug IDs: CSCth81055, CSCth81055
GHSA
GHSA-5vgh-45x2-wx9w: Memory leak in the IKEv1 implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2013-1144 [HIGH] GHSA-5vgh-45x2-wx9w: Memory leak in the IKEv1 implementation in Cisco IOS 15
Memory leak in the IKEv1 implementation in Cisco IOS 15.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified (1) IPv4 or (2) IPv6 IKE packets, aka Bug ID CSCth81055.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-03-28
Published