ID

VAR-201310-0526


CVE

CVE-2013-5543


TITLE

Cisco ASR 1000 Runs on series devices Cisco IOS XE Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2013-004964

DESCRIPTION

Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via malformed ICMP error packets associated with a (1) TCP or (2) UDP session that is under inspection by the Zone-Based Firewall (ZBFW) component, aka Bug ID CSCtt26470. Cisco ASR 1000 Runs on series devices Cisco IOS XE There is a service disruption ( Device reload ) There are vulnerabilities that are put into a state. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches. A security vulnerability exists in the Cisco IOS XE's Zone-Based Firewall (ZBFW) TCP or UDP functionality. Cisco IOS XE is prone to a remote denial-of-service vulnerability. Successful exploits may allow an attackers to cause a reload of the affected devices, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCtt26470

Trust: 2.52

sources: NVD: CVE-2013-5543 // JVNDB: JVNDB-2013-004964 // CNVD: CNVD-2013-14212 // BID: 63443 // VULHUB: VHN-65545

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-14212

AFFECTED PRODUCTS

vendor:ciscomodel:ios xescope:eqversion:3.4.0as

Trust: 1.6

vendor:ciscomodel:ios xescope:eqversion:3.4.0s

Trust: 1.6

vendor:ciscomodel:ios xescope:eqversion:3.4.1s

Trust: 1.6

vendor:ciscomodel:asr 1004scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1006scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1002scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1023 routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1002-xscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1001scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:ios xescope:eqversion:3.4

Trust: 0.9

vendor:ciscomodel:ios xescope:eqversion:3.4.2s

Trust: 0.8

vendor:ciscomodel:ios xescope:ltversion:3.5

Trust: 0.8

vendor:ciscomodel:asr 1002-x routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1006 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:ios xescope:ltversion:3.4

Trust: 0.8

vendor:ciscomodel:asr 1001 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1023 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1002 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:ios xescope:eqversion:3.5.1s

Trust: 0.8

vendor:ciscomodel:asr 1004 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:ios xe 3.5.1sscope:neversion: -

Trust: 0.3

vendor:ciscomodel:ios xe 3.4.2sscope:neversion: -

Trust: 0.3

sources: CNVD: CNVD-2013-14212 // BID: 63443 // JVNDB: JVNDB-2013-004964 // CNNVD: CNNVD-201310-721 // NVD: CVE-2013-5543

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-5543
value: HIGH

Trust: 1.0

NVD: CVE-2013-5543
value: HIGH

Trust: 0.8

CNVD: CNVD-2013-14212
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201310-721
value: HIGH

Trust: 0.6

VULHUB: VHN-65545
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-5543
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2013-14212
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-65545
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2013-14212 // VULHUB: VHN-65545 // JVNDB: JVNDB-2013-004964 // CNNVD: CNNVD-201310-721 // NVD: CVE-2013-5543

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-65545 // JVNDB: JVNDB-2013-004964 // NVD: CVE-2013-5543

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-721

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201310-721

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004964

PATCH

title:cisco-sa-20131030-asr1000url:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131030-asr1000

Trust: 0.8

title:31452url:http://tools.cisco.com/security/center/viewAlert.x?alertId=31452

Trust: 0.8

title:cisco-sa-20131030-asr1000url:http://www.cisco.com/cisco/web/support/JP/112/1120/1120847_cisco-sa-20131030-asr1000-j.html

Trust: 0.8

title:Patch for Cisco IOS XE Software Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/40650

Trust: 0.6

title:Cisco IOS XE Remediation measures for denial of service vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=164605

Trust: 0.6

sources: CNVD: CNVD-2013-14212 // JVNDB: JVNDB-2013-004964 // CNNVD: CNNVD-201310-721

EXTERNAL IDS

db:NVDid:CVE-2013-5543

Trust: 3.4

db:BIDid:63443

Trust: 1.0

db:JVNDBid:JVNDB-2013-004964

Trust: 0.8

db:CNNVDid:CNNVD-201310-721

Trust: 0.7

db:CNVDid:CNVD-2013-14212

Trust: 0.6

db:VULHUBid:VHN-65545

Trust: 0.1

sources: CNVD: CNVD-2013-14212 // VULHUB: VHN-65545 // BID: 63443 // JVNDB: JVNDB-2013-004964 // CNNVD: CNNVD-201310-721 // NVD: CVE-2013-5543

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20131030-asr1000

Trust: 2.3

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-5543

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-5543

Trust: 0.8

sources: CNVD: CNVD-2013-14212 // VULHUB: VHN-65545 // JVNDB: JVNDB-2013-004964 // CNNVD: CNNVD-201310-721 // NVD: CVE-2013-5543

CREDITS

Cisco

Trust: 0.3

sources: BID: 63443

SOURCES

db:CNVDid:CNVD-2013-14212
db:VULHUBid:VHN-65545
db:BIDid:63443
db:JVNDBid:JVNDB-2013-004964
db:CNNVDid:CNNVD-201310-721
db:NVDid:CVE-2013-5543

LAST UPDATE DATE

2024-11-23T22:31:22.195000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-14212date:2013-11-04T00:00:00
db:VULHUBid:VHN-65545date:2013-11-01T00:00:00
db:BIDid:63443date:2013-10-30T00:00:00
db:JVNDBid:JVNDB-2013-004964date:2013-11-05T00:00:00
db:CNNVDid:CNNVD-201310-721date:2021-10-08T00:00:00
db:NVDid:CVE-2013-5543date:2024-11-21T01:57:40.387

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-14212date:2013-11-04T00:00:00
db:VULHUBid:VHN-65545date:2013-10-31T00:00:00
db:BIDid:63443date:2013-10-30T00:00:00
db:JVNDBid:JVNDB-2013-004964date:2013-11-05T00:00:00
db:CNNVDid:CNNVD-201310-721date:2013-10-31T00:00:00
db:NVDid:CVE-2013-5543date:2013-10-31T21:55:02.830