CVE-2013-6981
published 2013-12-28CVE-2013-6981: Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID…
PriorityP426medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
3.03%
86.1th percentile
Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID CSCul00709.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | <= 3.7s\(.1\) | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
vendor_cisco5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Crafted MPLS IP Fragmentation Denial of Service Vulnerability
vendor_cisco·2013-12-24·CVSS 5.4
CVE-2013-6981 [MEDIUM] CWE-20 Cisco IOS XE Crafted MPLS IP Fragmentation Denial of Service Vulnerability
Cisco IOS XE Crafted MPLS IP Fragmentation Denial of Service Vulnerability
A vulnerability in the Multiprotocol Label Switching (MPLS) IP fragmentation function of Cisco IOS XE could allow an unauthenticated, remote attacker to cause the Cisco Packet Processor to crash.
The vulnerability is due to input validation processing of the crafted MPLS IP packets. An attacker could exploit this vulnerability by injecting specifically crafted MPLS IP packets that are subject to MPLS fragmentation. An exploit could allow the attacker to cause the Cisco Packet Processor process to crash in Cisco IOS XE software.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, it is likely that an attacker would need access to trusted, inter
GHSA
GHSA-h3w4-8qq4-m4j7: Cisco IOS XE 3
ghsa_unreviewed·2022-05-17
CVE-2013-6981 [MEDIUM] CWE-20 GHSA-h3w4-8qq4-m4j7: Cisco IOS XE 3
Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID CSCul00709.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/101423http://secunia.com/advisories/56206http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6981http://tools.cisco.com/security/center/viewAlert.x?alertId=32281http://www.securityfocus.com/bid/64514http://www.securitytracker.com/id/1029538http://osvdb.org/101423http://secunia.com/advisories/56206http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6981http://tools.cisco.com/security/center/viewAlert.x?alertId=32281http://www.securityfocus.com/bid/64514http://www.securitytracker.com/id/1029538
2013-12-28
Published