CVE-2013-5552
published 2013-11-13CVE-2013-5552: Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote…
PriorityP434medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.18%
64.3th percentile
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 12.4\(24\)mdb14 | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x583-rp6c-xwgv: Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2013-5552 [MEDIUM] GHSA-x583-rp6c-xwgv: Cisco IOS 12
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.
Cisco
Cisco Content Services Gateway Traffic Bypass Vulnerability
vendor_cisco·2013-11-11·CVSS 6.4
CVE-2013-5552 [MEDIUM] CWE-264 Cisco Content Services Gateway Traffic Bypass Vulnerability
Cisco Content Services Gateway Traffic Bypass Vulnerability
A vulnerability in the parse error drop function of the Cisco Content Services Gateway (CSG) could allow an unauthenticated, remote attacker to bypass configured policies.
The vulnerability is due to invalid processing in the parse error drop function. An attacker could exploit this vulnerability by sending a specific sequence of packets. An exploit could allow the attacker to potentially bypass access policies.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, it is likely that an attacker would need access to trusted, internal networks in which the targeted device may reside to send a sequence of packets to be processed by the device. This access requirem
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-13
Published