CVE-2013-5553
published 2013-11-08CVE-2013-5553: Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.90%
77.6th percentile
Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs CSCuc42558 and CSCug25383.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-86p4-r53w-954v: Multiple memory leaks in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2013-5553 [HIGH] GHSA-86p4-r53w-954v: Multiple memory leaks in Cisco IOS 15
Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs CSCuc42558 and CSCug25383.
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·2013-11-06·CVSS 7.8
CVE-2013-5553 [HIGH] CWE-20 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
A vulnerability exists in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device or cause memory leaks that may result in system instabilities. To exploit this vulnerability, affected devices must be configured to process SIP messages. Limited Cisco IOS Software releases are affected.
Cisco has released software updates that address this vulnerability.
There are no workarounds for devices that must run SIP; however, mitigations are available to limit exposure to the vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurit
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco
CVE-2013-5553 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
CVE-2013-5553: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
A vulnerability exists in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device or cause memory leaks that may result in system instabilities. To exploit this vulnerability, affected devices must be configured to process SIP messages. Limited Cisco IOS Software releases are affected. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-20, CWE-20
Bug IDs: CSCuc42558, CSCuc42558, CSCug25383
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-08
Published