CVE-2013-5477
published 2013-09-27CVE-2013-5477: The T1/E1 driver-queue functionality in Cisco IOS 12.2 and 15.0 through 15.3, when an HDLC32 driver is used, allows remote attackers to cause a denial of…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.89%
77.4th percentile
The T1/E1 driver-queue functionality in Cisco IOS 12.2 and 15.0 through 15.3, when an HDLC32 driver is used, allows remote attackers to cause a denial of service (interface queue wedge) via bursty network traffic, aka Bug ID CSCub67465.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Queue Wedge Denial of Service Vulnerability
vendor_cisco·2013-09-25·CVSS 7.8
CVE-2013-5477 [HIGH] CWE-399 Cisco IOS Software Queue Wedge Denial of Service Vulnerability
Cisco IOS Software Queue Wedge Denial of Service Vulnerability
A vulnerability in the T1/E1 driver queue implementation of Cisco IOS Software could allow an unauthenticated, remote attacker to cause an interface wedge condition, which could lead to loss of connectivity, loss of routing protocol adjacency, and could result in a denial of service (DoS) scenario.
The vulnerability is due to incorrect implementation of the T1/E1 driver queue. An attacker could exploit this vulnerability by sending bursty traffic through the affected interface driver. Repeated exploitation could cause a DoS condition.
Workarounds to mitigate this vulnerability are available.
Cisco has released software updates that address this vulnerability. This advisory is available at the following link:
https://sec.clo
Cisco
Cisco IOS Software Queue Wedge Denial of Service Vulnerability
vendor_cisco
CVE-2013-5477 Cisco IOS Software Queue Wedge Denial of Service Vulnerability
CVE-2013-5477: Cisco IOS Software Queue Wedge Denial of Service Vulnerability
A vulnerability in the T1/E1 driver queue implementation of Cisco IOS Software could allow an unauthenticated, remote attacker to cause an interface wedge condition, which could lead to loss of connectivity, loss of routing protocol adjacency, and could result in a denial of service (DoS) scenario. The vulnerability is due to incorrect implementation of the T1/E1 driver queue. An attacker could exploit this vulnerability by sending bursty traffic through the affected interface driver. Repeated exploitation could cause a DoS condition.
CWE: CWE-399, CWE-399
Bug IDs: CSCub67465, CSCub67465
GHSA
GHSA-hpvx-4qg5-5q4q: The T1/E1 driver-queue functionality in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2013-5477 [HIGH] CWE-20 GHSA-hpvx-4qg5-5q4q: The T1/E1 driver-queue functionality in Cisco IOS 12
The T1/E1 driver-queue functionality in Cisco IOS 12.2 and 15.0 through 15.3, when an HDLC32 driver is used, allows remote attackers to cause a denial of service (interface queue wedge) via bursty network traffic, aka Bug ID CSCub67465.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-09-27
Published