CVE-2013-5549
published 2013-10-25CVE-2013-5549: Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows…
PriorityP430high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.66%
74.2th percentile
Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCuh30380.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR Software Route Processor Denial of Service Vulnerability
vendor_cisco·2013-10-23·CVSS 7.1
CVE-2013-5549 [HIGH] CWE-362 Cisco IOS XR Software Route Processor Denial of Service Vulnerability
Cisco IOS XR Software Route Processor Denial of Service Vulnerability
Cisco IOS XR Software Releases 3.3.0 to 4.2.0 contain a vulnerability when handling fragmented packets that could result in a denial of service (DoS) condition of the Cisco CRS Route Processor cards listed in the "Affected Products" section of this advisory.
The vulnerability is due to improper handling of fragmented packets. The vulnerability could cause the route processor, which processes the packets, to be unable to transmit packets to the fabric.
Customers that are running version 4.2.1 or later of Cisco IOS XR Software, or that have previously installed the Software Maintenance Upgrades (SMU) for Cisco bug ID CSCtz62593 are not affected by this vulnerability.
Cisco has released software updates that address thi
Cisco
Cisco IOS XR Software Route Processor Denial of Service Vulnerability
vendor_cisco
CVE-2013-5549 Cisco IOS XR Software Route Processor Denial of Service Vulnerability
CVE-2013-5549: Cisco IOS XR Software Route Processor Denial of Service Vulnerability
Cisco IOS XR Software Releases 3.3.0 to 4.2.0 contain a vulnerability when handling fragmented packets that could result in a denial of service (DoS) condition of the Cisco CRS Route Processor cards listed in the "
CWE: CWE-362, CWE-362
Bug IDs: CSCuh30380, CSCtz62593, CSCuh30380, CSCtz62593
GHSA
GHSA-rmqj-585g-98v7: Cisco IOS XR 3
ghsa_unreviewed·2022-05-17
CVE-2013-5549 [HIGH] GHSA-rmqj-585g-98v7: Cisco IOS XR 3
Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCuh30380.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-10-25
Published