PT-2013-6218 · Cisco · Cisco Ios Xe

Published

2013-12-24

·

Updated

2016-09-15

·

CVE-2013-6981

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XE versions 3.7S(.1) and earlier
Description A vulnerability in the Multiprotocol Label Switching (MPLS) IP fragmentation function could allow an unauthenticated, remote attacker to cause the Cisco Packet Processor to crash. The issue is due to input validation processing of crafted MPLS IP packets. An attacker could exploit this by injecting specifically crafted MPLS IP packets subject to MPLS fragmentation, potentially allowing them to crash the Cisco Packet Processor process in Cisco IOS XE software. To exploit this, an attacker would likely need access to trusted, internal networks to send crafted packets to the targeted device.
Recommendations For Cisco IOS XE versions 3.7S(.1) and earlier, update to a newer version that includes the fix for this issue, as indicated by Cisco's security notice and software updates. As a temporary workaround, consider restricting access to internal networks to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6981

Affected Products

Cisco Ios Xe