Lucene search

K
cveCiscoCVE-2013-5469
HistoryAug 30, 2013 - 8:55 p.m.

CVE-2013-5469

2013-08-3020:55:08
CWE-119
cisco
web.nvd.nist.gov
32
4
cisco
ios
tcp
implementation
denial of service
vulnerability
nvd
cve-2013-5469

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

High

EPSS

0.012

Percentile

85.1%

The TCP implementation in Cisco IOS does not properly implement the transitions from the ESTABLISHED state to the CLOSED state, which allows remote attackers to cause a denial of service (flood of ACK packets) via a crafted series of ACK and FIN packets, aka Bug ID CSCtz14399.

Affected configurations

Nvd
Node
ciscoiosMatch-
VendorProductVersionCPE
ciscoios-cpe:2.3:o:cisco:ios:-:*:*:*:*:*:*:*

Social References

More

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

High

EPSS

0.012

Percentile

85.1%

Related for CVE-2013-5469