CVE-2013-5476
published 2013-09-27CVE-2013-5476: The Zone-Based Firewall (ZFW) feature in Cisco IOS 15.1 through 15.2, when content filtering or HTTP ALG inspection is enabled, allows remote attackers to…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.89%
77.4th percentile
The Zone-Based Firewall (ZFW) feature in Cisco IOS 15.1 through 15.2, when content filtering or HTTP ALG inspection is enabled, allows remote attackers to cause a denial of service (device reload or hang) via crafted IPv4 HTTP traffic, aka Bug ID CSCtx56174.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7w76-v7jx-gcpv: The Zone-Based Firewall (ZFW) feature in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2013-5476 [HIGH] CWE-20 GHSA-7w76-v7jx-gcpv: The Zone-Based Firewall (ZFW) feature in Cisco IOS 15
The Zone-Based Firewall (ZFW) feature in Cisco IOS 15.1 through 15.2, when content filtering or HTTP ALG inspection is enabled, allows remote attackers to cause a denial of service (device reload or hang) via crafted IPv4 HTTP traffic, aka Bug ID CSCtx56174.
Cisco
Cisco IOS Software Zone-Based Firewall and Content Filtering Vulnerability
vendor_cisco·2013-09-25·CVSS 7.8
CVE-2013-5476 [HIGH] CWE-20 Cisco IOS Software Zone-Based Firewall and Content Filtering Vulnerability
Cisco IOS Software Zone-Based Firewall and Content Filtering Vulnerability
A vulnerability in the Zone-Based Firewall (ZBFW) component of Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to hang or reload.
The vulnerability is due to improper processing of specific HTTP packets when the device is configured for either Cisco IOS Content Filtering or HTTP application layer gateway (ALG) inspection. An attacker could exploit this vulnerability by sending specific HTTP packets through an affected device. An exploit could allow the attacker to cause an affected device to hang or reload.
Cisco has released software updates that address this vulnerability.
Workarounds that mitigate this vulnerability are not available.
This advisory is available
Cisco
Cisco IOS Software Zone-Based Firewall and Content Filtering Vulnerability
vendor_cisco
CVE-2013-5476 Cisco IOS Software Zone-Based Firewall and Content Filtering Vulnerability
CVE-2013-5476: Cisco IOS Software Zone-Based Firewall and Content Filtering Vulnerability
A vulnerability in the Zone-Based Firewall (ZBFW) component of Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to hang or reload. The vulnerability is due to improper processing of specific HTTP packets when the device is configured for either Cisco IOS Content Filtering or HTTP application layer gateway (ALG) inspection. An attacker could exploit this vulnerability by sending specific HTTP packets through an affected device. An exploit could allow the attacker to cause an affected device to hang or reload. Cisco has released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCtx56174, CSCtx56174
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-09-27
Published