CVE-2013-6693
published 2013-11-22CVE-2013-6693: The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service…
PriorityP425medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
1.13%
62.5th percentile
The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.3\(3\)s | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
vendor_cisco5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8439-8j33-xpx5: The MLDP implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2013-6693 [MEDIUM] CWE-119 GHSA-8439-8j33-xpx5: The MLDP implementation in Cisco IOS 15
The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345.
Cisco
Cisco IOS Software MLDP Denial of Service Vulnerability
vendor_cisco·2013-11-21·CVSS 5.4
CVE-2013-6693 [MEDIUM] CWE-16 Cisco IOS Software MLDP Denial of Service Vulnerability
Cisco IOS Software MLDP Denial of Service Vulnerability
A vulnerability in MLDP processing of Cisco IOS Software on Cisco 7600 Series routers could allow an unauthenticated, remote attacker to cause a reload of the affected device, which could lead to a denial of service (DoS) condition.
The vulnerability is due to chunk corruption when MLDP and a large number of VRFs are configured on a device. An attacker could exploit this vulnerability by sending a large number of multicast flows over a number of configured VRF instances. An exploit could allow the attacker to cause a reload of the affected device and lead to a DoS condition.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker need to have the ability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-22
Published