PT-2013-1009 · Cisco · Cisco Ios
Published
2013-09-25
·
Updated
2013-10-07
·
CVE-2013-5474
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.2 through 12.4
Cisco IOS versions 15.0 through 15.3
Description
The issue is caused by a race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation, allowing a remote attacker to cause a denial of service (device reload or hang) via fragmented IPv6 packets. An attacker could exploit this by sending a crafted stream of valid IPv6 fragments, potentially resulting in a sustained denial of service condition.
Recommendations
For Cisco IOS versions 12.2 through 12.4, update to a fixed version to address the vulnerability.
For Cisco IOS versions 15.0 through 15.3, update to a fixed version to address the vulnerability.
As a temporary workaround, consider restricting access to the VFR feature for IPv6 until a patch is available.
Fix
DoS
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios