CVE-2013-5503
published 2013-10-02CVE-2013-5503: The UDP process in Cisco IOS XR 4.3.1 does not free packet memory upon detecting full packet queues, which allows remote attackers to cause a denial of service…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.33%
68.1th percentile
The UDP process in Cisco IOS XR 4.3.1 does not free packet memory upon detecting full packet queues, which allows remote attackers to cause a denial of service (memory consumption) via UDP packets to listening ports, aka Bug ID CSCue69413.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR Software Memory Exhaustion Vulnerability
vendor_cisco·2013-10-02·CVSS 7.8
CVE-2013-5503 [HIGH] CWE-399 Cisco IOS XR Software Memory Exhaustion Vulnerability
Cisco IOS XR Software Memory Exhaustion Vulnerability
Cisco IOS XR Software version 4.3.1 contains a vulnerability that could result in complete packet memory exhaustion. Successful exploitation could render critical services on the affected device unable to allocate packets resulting in a denial of service (DoS) condition.
Cisco has released software updates that address this vulnerability.
Workarounds that mitigate this vulnerability are available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131002-iosxr
Cisco
Cisco IOS XR Software Memory Exhaustion Vulnerability
vendor_cisco
CVE-2013-5503 Cisco IOS XR Software Memory Exhaustion Vulnerability
CVE-2013-5503: Cisco IOS XR Software Memory Exhaustion Vulnerability
Cisco IOS XR Software version 4.3.1 contains a vulnerability that could result in complete packet memory exhaustion. Successful exploitation could render critical services on the affected device unable to allocate packets resulting in a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCue69413, CSCue69413, CSCue69413, CSCue69413, CSCue69413
GHSA
GHSA-rcf2-qf65-j8cp: The UDP process in Cisco IOS XR 4
ghsa_unreviewed·2022-05-17
CVE-2013-5503 [HIGH] GHSA-rcf2-qf65-j8cp: The UDP process in Cisco IOS XR 4
The UDP process in Cisco IOS XR 4.3.1 does not free packet memory upon detecting full packet queues, which allows remote attackers to cause a denial of service (memory consumption) via UDP packets to listening ports, aka Bug ID CSCue69413.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-10-02
Published