CVE-2013-6981Improper Input Validation in Cisco IOS XE

Severity
5.4MEDIUMNVD
EPSS
2.8%
top 13.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 28
Latest updateMay 17

Description

Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID CSCul00709.

CVSS vector

AV:N/AC:H/C:N/I:N/A:CExploitability: 4.9 | Impact: 6.9

Affected Packages1 packages

NVDcisco/ios_xe3.7s\(.1\)+28

🔴Vulnerability Details

2
GHSA
GHSA-h3w4-8qq4-m4j7: Cisco IOS XE 32022-05-17
CVEList
CVE-2013-6981: Cisco IOS XE 32013-12-28

📋Vendor Advisories

1
Cisco
Cisco IOS XE Crafted MPLS IP Fragmentation Denial of Service Vulnerability2013-12-24
CVE-2013-6981 — Improper Input Validation in Cisco | cvebase