CVE-2013-5566
published 2013-11-08CVE-2013-5566: Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.90%
77.5th percentile
Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header (AH) authentication in a Virtual Router Redundancy Protocol (VRRP) frame, aka Bug ID CSCte27874.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | <= 5.0 | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco MDS 9000 NX-OS Software Denial of Service Vulnerability
vendor_cisco·2013-11-06·CVSS 5.0
CVE-2013-5566 [MEDIUM] CWE-399 Cisco MDS 9000 NX-OS Software Denial of Service Vulnerability
Cisco MDS 9000 NX-OS Software Denial of Service Vulnerability
A vulnerability in the supervisor of the Cisco MDS Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of Virtual Router Redundancy Protocol (VRRP) frames. An attacker could exploit this vulnerability by sending a VRRP frame with Authentication Header (AH) authentication. An exploit could allow an attacker to drive CPU utilization over 90 percent, causing the supervisor to be slow to respond. The CPU does not recover until the VRRP service is restarted via a system switchover or restart.
Cisco has confirmed the vulnerability in a security notice and released software updates.
Cisco indicates through the CVSS score that functional
GHSA
GHSA-j3xh-96gv-642p: Cisco NX-OS 5
ghsa_unreviewed·2022-05-17
CVE-2013-5566 [MEDIUM] CWE-119 GHSA-j3xh-96gv-642p: Cisco NX-OS 5
Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header (AH) authentication in a Virtual Router Redundancy Protocol (VRRP) frame, aka Bug ID CSCte27874.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-08
Published