Lucene search

K
cveCiscoCVE-2013-1136
HistoryMay 13, 2013 - 11:50 a.m.

CVE-2013-1136

2013-05-1311:50:48
CWE-399
cisco
web.nvd.nist.gov
25
cisco
ios
crypto engine
denial of service
vulnerability
cve-2013-1136
nvd
asr
route processor

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:N/I:N/A:C

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

40.4%

The crypto engine process in Cisco IOS on Aggregation Services Router (ASR) Route Processor 2 does not properly manage memory, which allows local users to cause a denial of service (route processor crash) by creating multiple tunnels and then examining encryption statistics, aka Bug ID CSCuc52193.

Affected configurations

Nvd
Node
ciscoiosMatch-
AND
ciscoaggregation_services_router_route_processorMatch2
VendorProductVersionCPE
ciscoios-cpe:2.3:o:cisco:ios:-:*:*:*:*:*:*:*
ciscoaggregation_services_router_route_processor2cpe:2.3:h:cisco:aggregation_services_router_route_processor:2:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:N/I:N/A:C

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

40.4%

Related for CVE-2013-1136