6.4
CVSSv2

CVE-2013-5552

Published: 13/11/2013 Updated: 14/11/2013
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Cisco IOS 12.4(24)MDB9 and previous versions on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote malicious users to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 12.4\\(24\\)mdb10

cisco ios 12.4\\(24\\)mdb12

cisco ios 12.4\\(24\\)mda6

cisco ios 12.4\\(24\\)mda8

cisco ios 12.4\\(24\\)md8

cisco ios 12.4\\(24\\)md

cisco ios

cisco ios 12.4\\(24\\)mda10

cisco ios 12.4\\(24\\)mda11

cisco ios 12.4\\(24\\)mda12

cisco ios 12.4\\(24\\)mda13

cisco ios 12.4\\(24\\)md2

cisco ios 12.4\\(24\\)md1

cisco ios 12.4\\(24\\)md3

cisco ios 12.4\\(24\\)md4

cisco ios 12.4mda12

cisco ios 12.4\\(24\\)md5

cisco ios 12.4\\(24\\)md5a

cisco ios 12.4\\(24\\)md6

cisco ios 12.4\\(24\\)mdb11

cisco ios 12.4\\(24\\)mdb13

cisco ios 12.4\\(24\\)mda7

cisco ios 12.4\\(24\\)mda9

cisco ios 12.4\\(24\\)md7

cisco ios 12.4\\(24\\)md9

cisco content_services_gateway -

Vendor Advisories

A vulnerability in the parse error drop function of the Cisco Content Services Gateway (CSG) could allow an unauthenticated, remote attacker to bypass configured policies The vulnerability is due to invalid processing in the parse error drop function An attacker could exploit this vulnerability by sending a specific sequence of packets An explo ...