7.1
CVSSv2

CVE-2013-6704

Published: 03/12/2013 Updated: 15/09/2016
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco IOS XE does not properly manage memory for TFTP UDP flows, which allows remote malicious users to cause a denial of service (memory consumption) via TFTP (1) client or (2) server traffic, aka Bug IDs CSCuh09324 and CSCty42686.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe -

Vendor Advisories

A vulnerability in the flow manager code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause flow manager to hold UDP sessions in its table The vulnerability is due to not releasing memory for flows generated by TFTP UDP traffic An attacker could exploit this vulnerability by either starting a local TFTP transaction ...