CVE-2013-5480
published 2013-09-27CVE-2013-5480: The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload)…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.33%
68.1th percentile
The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka Bug ID CSCuf28733.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9662-9hfv-c3vr: The DNS-over-TCP implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2013-5480 [HIGH] CWE-20 GHSA-9662-9hfv-c3vr: The DNS-over-TCP implementation in Cisco IOS 12
The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka Bug ID CSCuf28733.
Cisco
Cisco IOS Software Network Address Translation Vulnerabilities
vendor_cisco·2013-09-25·CVSS 7.8
CVE-2013-5479 [HIGH] CWE-119 Cisco IOS Software Network Address Translation Vulnerabilities
Cisco IOS Software Network Address Translation Vulnerabilities
The Cisco IOS Software implementation of the network address translation (NAT) feature contains three vulnerabilities when translating IP packets that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130925-nat
Note: The September 25, 2013, Cisco IOS Software Security Advisory bundled publication includes eight Cisco Security Advisories. All advisories address vulnerabilities in Cisco IOS Software. Each Cisco
Cisco
Cisco IOS Software Network Address Translation Vulnerabilities
vendor_cisco
CVE-2013-5480 Cisco IOS Software Network Address Translation Vulnerabilities
CVE-2013-5480: Cisco IOS Software Network Address Translation Vulnerabilities
The Cisco IOS Software implementation of the network address translation (NAT) feature contains three vulnerabilities when translating IP packets that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-119, CWE-119
Bug IDs: CSCtn53730, CSCtq14817, CSCuf28733, CSCtn53730, CSCuf28733
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-09-27
Published