PT-2013-5587 · Cisco · Cisco Ios Xr
Published
2013-10-02
·
Updated
2013-10-03
·
CVE-2013-5503
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XR Software version 4.3.1
Description
The issue is related to the UDP process in Cisco IOS XR, which does not free packet memory upon detecting full packet queues. This allows remote attackers to cause a denial of service (memory consumption) via UDP packets to listening ports. Successful exploitation could render critical services on the affected device unable to allocate packets, resulting in a denial of service (DoS) condition.
Recommendations
For Cisco IOS XR Software version 4.3.1, update to a newer version that addresses this issue, as software updates have been released by Cisco. Alternatively, consider applying available workarounds that mitigate this vulnerability.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xr