6.3
CVSSv2

CVE-2013-6692

Published: 22/11/2013 Updated: 22/11/2013
CVSS v2 Base Score: 6.3 | Impact Score: 6.9 | Exploitability Score: 6.8
VMScore: 561
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:C

Vulnerability Summary

Cisco IOS XE 3.8S(.2) and previous versions does not properly use a DHCP pool during assignment of an IP address, which allows remote authenticated users to cause a denial of service (device reload) via an AAA packet that triggers an address requirement, aka Bug ID CSCuh04949.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 3.8s\\(.0\\)

cisco ios xe 3.7.0s

cisco ios xe 3.7.1s

cisco ios xe 3.7.2s

cisco ios xe 3.8s\\(.1\\)

cisco ios xe 3.8.0s

cisco ios xe

Vendor Advisories

A vulnerability in a DHCP function that assigns IP addresses to AAA clients on Cisco IOS XE Software could allow an authenticated, remote attacker to cause a reload of the affected device The vulnerability is due to improper processing of AAA packets that require IP address assignment from a DHCP pool An attacker could exploit this vulnerability ...