CVE-2013-5552

Published Nov 13, 2013

Last updated 11 years ago

Overview

Description
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.
Source
ykramarz@cisco.com
NVD status
Analyzed

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
6.4
Impact score
4.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:P/A:N

Weaknesses

nvd@nist.gov
CWE-264

Evaluator

Comment
Additional versions CISCO IOS are vulnerable per http://tools.cisco.com/security/center/viewAlert.x?alertId=31715
Impact
-
Solution
-

Configurations