7.8
CVSSv2

CVE-2013-5475

Published: 27/09/2013 Updated: 07/10/2013
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco IOS 12.2 up to and including 12.4 and 15.0 up to and including 15.3, and IOS XE 2.1 up to and including 3.9, allows remote malicious users to cause a denial of service (device reload) via crafted DHCP packets that are processed locally by a (1) server or (2) relay agent, aka Bug ID CSCug31561.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 2.2.1

cisco ios xe 2.2.2

cisco ios xe 2.2.3

cisco ios xe 2.3.0

cisco ios xe 2.6.1

cisco ios xe 2.6.2

cisco ios xe 3.1.0s

cisco ios xe 3.1.0sg

cisco ios xe 3.1.1s

cisco ios xe 3.2.3sg

cisco ios xe 3.2.4sg

cisco ios xe 3.3.0s

cisco ios xe 3.3.0sg

cisco ios xe 3.5.1s

cisco ios xe 3.5.2s

cisco ios xe 3.5.xs

cisco ios xe 3.6.0s

cisco ios xe 2.1.1

cisco ios xe 2.3.1t

cisco ios xe 2.4.0

cisco ios xe 2.5.0

cisco ios xe 2.5.2

cisco ios xe 3.1.1sg

cisco ios xe 3.1.3s

cisco ios xe 3.2.1sg

cisco ios xe 3.2.2sg

cisco ios xe 3.3.1s

cisco ios xe 3.3.2s

cisco ios xe 3.4.4s

cisco ios xe 3.4.xs

cisco ios xe 3.6.2s

cisco ios xe 3.7.1s

cisco ios xe 2.4.1

cisco ios xe 2.4.2

cisco ios xe 2.4.3

cisco ios xe 2.4.4

cisco ios xe 3.2.00.xo.15.0\\(2\\)xo

cisco ios xe 3.2.0s

cisco ios xe 3.2.0sg

cisco ios xe 3.2.0xo

cisco ios xe 3.4.0as

cisco ios xe 3.4.0s

cisco ios xe 3.4.1s

cisco ios xe 3.4.2s

cisco ios xe 3.4.3s

cisco ios xe 2.1.0

cisco ios xe 2.1.2

cisco ios xe 2.3.1

cisco ios xe 2.3.2

cisco ios xe 2.5.1

cisco ios xe 2.6.0

cisco ios xe 3.1.2s

cisco ios xe 3.1.4s

cisco ios xe 3.2.1s

cisco ios xe 3.2.2s

cisco ios xe 3.3.1sg

cisco ios xe 3.3.3s

cisco ios xe 3.4.5s

cisco ios xe 3.5.0s

cisco ios xe 3.6.1s

cisco ios xe 3.7.0s

cisco ios 15.3

cisco ios 15.2

cisco ios 15.1

cisco ios 15.0

cisco ios 12.3

cisco ios 12.4

cisco ios 12.2

Vendor Advisories

A vulnerability in the DHCP implementation of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition The vulnerability occurs during the parsing of crafted DHCP packets An attacker could exploit this vulnerability by sending crafted DHCP packets to an affected dev ...