CVE-2013-5474
published 2013-09-27CVE-2013-5474: Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.3 allows remote attackers…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.44%
70.5th percentile
Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.3 allows remote attackers to cause a denial of service (device reload or hang) via fragmented IPv6 packets, aka Bug ID CSCud64812.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software IPv6 Virtual Fragmentation Reassembly Denial of Service Vulnerability
vendor_cisco·2013-09-25·CVSS 7.8
CVE-2013-5474 [HIGH] CWE-362 Cisco IOS Software IPv6 Virtual Fragmentation Reassembly Denial of Service Vulnerability
Cisco IOS Software IPv6 Virtual Fragmentation Reassembly Denial of Service Vulnerability
A vulnerability in the implementation of the virtual fragmentation reassembly (VFR) feature for IP version 6 (IPv6) in Cisco IOS Software could allow an
unauthenticated, remote attacker to cause an affected device to hang or reload, resulting in a denial of service (DoS) condition.
The
vulnerability is due to a race condition while accessing the reassembly
queue for IPv6 fragments. An attacker could exploit this vulnerability
by sending a crafted stream of valid IPv6 fragments. Repeated
exploitation may result in a sustained DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds for this vulnerability.
This advisory is available at the following
Cisco
Cisco IOS Software IPv6 Virtual Fragmentation Reassembly Denial of Service Vulnerability
vendor_cisco
CVE-2013-5474 Cisco IOS Software IPv6 Virtual Fragmentation Reassembly Denial of Service Vulnerability
CVE-2013-5474: Cisco IOS Software IPv6 Virtual Fragmentation Reassembly Denial of Service Vulnerability
A vulnerability in the implementation of the virtual fragmentation reassembly (VFR) feature for IP version 6 (IPv6) in Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to hang or reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a race condition while accessing the reassembly queue for IPv6 fragments. An attacker could exploit this vulnerability by sending a crafted stream of valid IPv6 fragments. Repeated exploitation may result in a sustained DoS condition. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-362, CWE-362
Bug IDs: CSCud64812, CSCud64812
GHSA
GHSA-pj68-37fj-g5m7: Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2013-5474 [HIGH] CWE-362 GHSA-pj68-37fj-g5m7: Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12
Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.3 allows remote attackers to cause a denial of service (device reload or hang) via fragmented IPv6 packets, aka Bug ID CSCud64812.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-09-27
Published