PT-2013-4391 · Cisco · Cisco Ios

Published

2013-07-18

·

Updated

2017-11-29

·

CVE-2013-3436

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS (affected versions not specified)
Description The default configuration of the Group Encrypted Transport VPN (GET VPN) feature uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic flow. This allows remote attackers to bypass the encryption policy via certain uses of UDP port 848.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3436

Affected Products

Cisco Ios