CVE-2013-6692
published 2013-11-22CVE-2013-6692: Cisco IOS XE 3.8S(.2) and earlier does not properly use a DHCP pool during assignment of an IP address, which allows remote authenticated users to cause a…
PriorityP426medium6.3CVSS 2.0
AVNACMAuSCNINAC
EPSS
0.94%
57.2th percentile
Cisco IOS XE 3.8S(.2) and earlier does not properly use a DHCP pool during assignment of an IP address, which allows remote authenticated users to cause a denial of service (device reload) via an AAA packet that triggers an address requirement, aka Bug ID CSCuh04949.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | <= 3.8s\(.2\) | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.06.3MEDIUMAV:N/AC:M/Au:S/C:N/I:N/A:C
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software AAA DHCP Denial of Service Vulnerability
vendor_cisco·2013-11-21·CVSS 6.3
CVE-2013-6692 [MEDIUM] CWE-399 Cisco IOS XE Software AAA DHCP Denial of Service Vulnerability
Cisco IOS XE Software AAA DHCP Denial of Service Vulnerability
A vulnerability in a DHCP function that assigns IP addresses to AAA clients on Cisco IOS XE Software could allow an authenticated, remote attacker to cause a reload of the affected device.
The vulnerability is due to improper processing of AAA packets that require IP address assignment from a DHCP pool. An attacker could exploit this vulnerability by sending AAA packets to a device configured to authenticate and assign an address from a DHCP pool. An exploit could allow the attacker to cause a reload of the affected device.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker would need to authenticate to the targeted device. This access requir
GHSA
GHSA-6vv4-rrfh-pcgh: Cisco IOS XE 3
ghsa_unreviewed·2022-05-17
CVE-2013-6692 [MEDIUM] GHSA-6vv4-rrfh-pcgh: Cisco IOS XE 3
Cisco IOS XE 3.8S(.2) and earlier does not properly use a DHCP pool during assignment of an IP address, which allows remote authenticated users to cause a denial of service (device reload) via an AAA packet that triggers an address requirement, aka Bug ID CSCuh04949.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-22
Published