PT-2013-1009 · Cisco · Cisco Ios

Published

2013-09-25

·

Updated

2013-10-07

·

CVE-2013-5474

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.2 through 12.4 Cisco IOS versions 15.0 through 15.3
Description The issue is caused by a race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation, allowing a remote attacker to cause a denial of service (device reload or hang) via fragmented IPv6 packets. An attacker could exploit this by sending a crafted stream of valid IPv6 fragments, potentially resulting in a sustained denial of service condition.
Recommendations For Cisco IOS versions 12.2 through 12.4, update to a fixed version to address the vulnerability. For Cisco IOS versions 15.0 through 15.3, update to a fixed version to address the vulnerability. As a temporary workaround, consider restricting access to the VFR feature for IPv6 until a patch is available.

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00043
CVE-2013-5474

Affected Products

Cisco Ios