CVE-2013-5475Improper Input Validation in Cisco IOS

Severity
7.8HIGHNVD
EPSS
0.3%
top 45.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 27
Latest updateMay 17

Description

Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets that are processed locally by a (1) server or (2) relay agent, aka Bug ID CSCug31561.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages2 packages

NVDcisco/ios7 versions+6
NVDcisco/ios_xe61 versions+60

🔴Vulnerability Details

2
GHSA
GHSA-pgrq-7rj5-gx6x: Cisco IOS 122022-05-17
CVEList
CVE-2013-5475: Cisco IOS 122013-09-27

📋Vendor Advisories

1
Cisco
Cisco IOS Software DHCP Denial of Service Vulnerability2013-09-25
CVE-2013-5475 — Improper Input Validation in Cisco IOS | cvebase