CVE-2013-6686
published 2013-11-18CVE-2013-6686: The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via…
PriorityP426medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
1.50%
71.2th percentile
The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.3 | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_redhat7.5HIGH
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software SSL VPN Interface Queue Wedge Denial of Service Vulnerability
vendor_cisco·2013-11-13·CVSS 6.8
CVE-2013-6686 [MEDIUM] CWE-20 Cisco IOS Software SSL VPN Interface Queue Wedge Denial of Service Vulnerability
Cisco IOS Software SSL VPN Interface Queue Wedge Denial of Service Vulnerability
A vulnerability in the Datagram Transport Layer Security (DTLS) function of the Cisco IOS Software SSL VPN feature could allow an authenticated, remote attacker to cause the SSL VPN gateway interface to stop processing traffic when the queue is full, resulting in a denial of service (DoS) condition.
The vulnerability is due to improper processing of specific DTLS packets. An attacker could exploit this vulnerability by creating an SSL session and then sending crafted DTLS packets. An exploit could allow the attacker to cause the SSL VPN gateway interface to become full, resulting in a DoS condition.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this v
Red Hat
glibc: stack overflow in getaddrinfo()'s use of alloca()
vendor_redhat·2011-04-13·CVSS 7.5
CVE-2012-6686 [HIGH] CWE-121 glibc: stack overflow in getaddrinfo()'s use of alloca()
glibc: stack overflow in getaddrinfo()'s use of alloca()
[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2013-4357. Note: All CVE users should reference CVE-2013-4357 instead of this candidate.
Statement: This issue has already been addressed in Red Hat Enterprise Linux 5 via http://rhn.redhat.com/errata/RHBA-2013-0022.html and in Red Hat Enterprise Linux 6 via http://rhn.redhat.com/errata/RHBA-2012-0763.html
Package: glibc (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-7467-v6r8-xmjw: The SSL VPN implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2013-6686 [MEDIUM] CWE-20 GHSA-7467-v6r8-xmjw: The SSL VPN implementation in Cisco IOS 15
The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.
No detection rules found.
No public exploits indexed.
2013-11-18
Published