CVE-2013-1146
published 2013-03-28CVE-2013-1146: The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches allows remote attackers to cause a denial of service…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.33%
68.1th percentile
The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in Smart Install packets, aka Bug ID CSCub55790.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Smart Install Denial of Service Vulnerability
vendor_cisco·2013-03-27·CVSS 7.8
CVE-2013-1146 [HIGH] CWE-399 Cisco IOS Software Smart Install Denial of Service Vulnerability
Cisco IOS Software Smart Install Denial of Service Vulnerability
The Smart Install client feature in Cisco IOS Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Affected devices that are configured as Smart Install clients are vulnerable.
Cisco has released software updates that address this vulnerability. There are no workarounds for devices that have the Smart Install client feature enabled.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-smartinstall
Note: The March 27, 2013, Cisco IOS Software Security Advisory bundled publication includes seven Cisco Security Advisories. All advi
Cisco
Cisco IOS Software Smart Install Denial of Service Vulnerability
vendor_cisco
CVE-2013-1146 Cisco IOS Software Smart Install Denial of Service Vulnerability
CVE-2013-1146: Cisco IOS Software Smart Install Denial of Service Vulnerability
The Smart Install client feature in Cisco IOS Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. Affected devices that are configured as Smart Install clients are vulnerable. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCub55790, CSCub55790, CSCtj75729, CSCtj75729
GHSA
GHSA-j6vf-c5c5-5r47: The Smart Install client functionality in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2013-1146 [HIGH] CWE-119 GHSA-j6vf-c5c5-5r47: The Smart Install client functionality in Cisco IOS 12
The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in Smart Install packets, aka Bug ID CSCub55790.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-03-28
Published