7.1
CVSSv2

CVE-2013-5549

Published: 25/10/2013 Updated: 25/10/2013
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco IOS XR 3.8.1 up to and including 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote malicious users to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCuh30380.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xr 4.0.1

cisco ios xr 4.0.2

cisco ios xr 4.0.3

cisco ios xr 4.0.4

cisco ios xr 3.8.1

cisco ios xr 3.8.2

cisco ios xr 3.8.3

cisco ios xr 3.8.4

cisco ios xr 3.9.1

cisco ios xr 4.0.0

cisco ios xr 4.1

cisco ios xr 4.1.2

cisco ios xr 3.9.0

cisco ios xr 3.9.2

cisco ios xr 4.1.1

cisco ios xr 4.2.0

Vendor Advisories

Cisco IOS XR Software Releases 330 to 420 contain a vulnerability when handling fragmented packets that could result in a denial of service (DoS) condition of the Cisco CRS Route Processor cards listed in the "Affected Products" section of this advisory The vulnerability is due to improper handling of fragmented packets The vulnerability co ...