PT-2013-1009 · Cisco · Cisco Ios

Publicado

2013-09-25

·

Atualizado

2013-10-07

·

CVE-2013-5474

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.2 through 12.4 Cisco IOS versions 15.0 through 15.3
Description The issue is caused by a race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation, allowing a remote attacker to cause a denial of service (device reload or hang) via fragmented IPv6 packets. An attacker could exploit this by sending a crafted stream of valid IPv6 fragments, potentially resulting in a sustained denial of service condition.
Recommendations For Cisco IOS versions 12.2 through 12.4, update to a fixed version to address the vulnerability. For Cisco IOS versions 15.0 through 15.3, update to a fixed version to address the vulnerability. As a temporary workaround, consider restricting access to the VFR feature for IPv6 until a patch is available.

Correção

DoS

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2014-00043
CVE-2013-5474

Produtos afetados

Cisco Ios