Cisco IOS XE Software AAA DHCP Denial of Service Vulnerability

Related Vulnerabilities: CVE-2013-6692  

A vulnerability in a DHCP function that assigns IP addresses to AAA clients on Cisco IOS XE Software could allow an authenticated, remote attacker to cause a reload of the affected device. The vulnerability is due to improper processing of AAA packets that require IP address assignment from a DHCP pool. An attacker could exploit this vulnerability by sending AAA packets to a device configured to authenticate and assign an address from a DHCP pool. An exploit could allow the attacker to cause a reload of the affected device. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker would need to authenticate to the targeted device. This access requirement decreases the likelihood of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.