Lucene search

K
ciscoCiscoCISCO-SA-20131121-CVE-2013-6692
HistoryNov 21, 2013 - 8:14 p.m.

Cisco IOS XE Software AAA DHCP Denial of Service Vulnerability

2013-11-2120:14:42
tools.cisco.com
14

CVSS2

6.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:N/I:N/A:C

EPSS

0.001

Percentile

43.8%

A vulnerability in a DHCP function that assigns IP addresses to AAA clients on Cisco IOS XE Software could allow an authenticated, remote attacker to cause a reload of the affected device.

The vulnerability is due to improper processing of AAA packets that require IP address assignment from a DHCP pool. An attacker could exploit this vulnerability by sending AAA packets to a device configured to authenticate and assign an address from a DHCP pool. An exploit could allow the attacker to cause a reload of the affected device.

Cisco has confirmed the vulnerability in a security notice and released software updates.

To exploit this vulnerability, an attacker would need to authenticate to the targeted device. This access requirement decreases the likelihood of a successful exploit.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscocisco_iosMatch3.7sxe
OR
ciscocisco_iosMatch3.8sxe
OR
ciscocisco_iosMatch3.7.0sxe
OR
ciscocisco_iosMatch3.7.1sxe
OR
ciscocisco_iosMatch3.7.2sxe
OR
ciscocisco_iosMatch3.7.3sxe
OR
ciscocisco_iosMatch3.7.4sxe
OR
ciscocisco_iosMatch3.8.0sxe
OR
ciscocisco_iosMatch3.8.1sxe
OR
ciscocisco_iosMatch3.8.2sxe
VendorProductVersionCPE
ciscocisco_ios3.7scpe:2.3:o:cisco:cisco_ios:3.7s:xe:*:*:*:*:*:*
ciscocisco_ios3.8scpe:2.3:o:cisco:cisco_ios:3.8s:xe:*:*:*:*:*:*
ciscocisco_ios3.7.0scpe:2.3:o:cisco:cisco_ios:3.7.0s:xe:*:*:*:*:*:*
ciscocisco_ios3.7.1scpe:2.3:o:cisco:cisco_ios:3.7.1s:xe:*:*:*:*:*:*
ciscocisco_ios3.7.2scpe:2.3:o:cisco:cisco_ios:3.7.2s:xe:*:*:*:*:*:*
ciscocisco_ios3.7.3scpe:2.3:o:cisco:cisco_ios:3.7.3s:xe:*:*:*:*:*:*
ciscocisco_ios3.7.4scpe:2.3:o:cisco:cisco_ios:3.7.4s:xe:*:*:*:*:*:*
ciscocisco_ios3.8.0scpe:2.3:o:cisco:cisco_ios:3.8.0s:xe:*:*:*:*:*:*
ciscocisco_ios3.8.1scpe:2.3:o:cisco:cisco_ios:3.8.1s:xe:*:*:*:*:*:*
ciscocisco_ios3.8.2scpe:2.3:o:cisco:cisco_ios:3.8.2s:xe:*:*:*:*:*:*

CVSS2

6.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:N/I:N/A:C

EPSS

0.001

Percentile

43.8%

Related for CISCO-SA-20131121-CVE-2013-6692