CVE-2013-5546
Last modified
CVE-2013-5546 is a vulnerability of currently unknown severity. The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via large TCP packets that are processed by the (1) NAT or (2) ALG component, aka Bug ID CSCud72509.. EPSS estimates a 1.89% chance of exploitation in the next 30 days.
Description
The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via large TCP packets that are processed by the (1) NAT or (2) ALG component, aka Bug ID CSCud72509.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.7.0s |
| Cisco | Ios Xe | 3.7.1s |
| Cisco | Ios Xe | 3.7.2s |
| Cisco | Ios Xe | 3.8.0s |
| Cisco | Asr 1001 | All versions |
| Cisco | Asr 1002 | All versions |
| Cisco | Asr 1002-X | All versions |
| Cisco | Asr 1004 | All versions |
| Cisco | Asr 1006 | All versions |
| Cisco | Asr 1023 Router | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-5546?
How severe is CVE-2013-5546?
How do I fix CVE-2013-5546?
Are you affected by CVE-2013-5546?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
