Lucene search

K
ciscoCiscoCISCO-SA-20130411-CVE-2013-1189
HistoryApr 11, 2013 - 9:00 p.m.

Cisco uBR10000 Series IPv4/IPv6 Dual Stack Vulnerability

2013-04-1121:00:00
tools.cisco.com
33

CVSS2

5.7

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:A/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.001

Percentile

30.1%

Cisco uBR10000 Series Universal Broadband Routers contain a vulnerability that could allow an unauthenticated, adjacent attacker to trigger the reload of the routing engine on the affected device.

An attacker could exploit this vulnerability by manipulating IPv4 and IPv6 address assignments on a dual-stack modem connected to the affected device.

Cisco has confirmed the vulnerability in a security notice and software updates are available.

To exploit the vulnerability, a dual-stack modem must be connected to an affected device. In addition, an attacker must have access to a trusted, internal network to manipulate the modem in a manner to trigger the vulnerability. This access requirement may reduce the likelihood of a successful attack.

Affected configurations

Vulners
Node
ciscocisco_7xx_routersMatchany
OR
ciscocisco_7xx_routersMatchany
VendorProductVersionCPE
ciscocisco_7xx_routersanycpe:2.3:h:cisco:cisco_7xx_routers:any:*:*:*:*:*:*:*

CVSS2

5.7

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:A/AC:M/Au:N/C:N/I:N/A:C

EPSS

0.001

Percentile

30.1%

Related for CISCO-SA-20130411-CVE-2013-1189