7.1

CVE-2013-1143

The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S, when MPLS-TE is enabled, allows remote attackers to cause a denial of service (incorrect memory access and device reload) via a traffic engineering PATH message in an RSVP packet, aka Bug ID CSCtg39957.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Version 12.2
Cisco ≫ Ios Version 15.0
Cisco ≫ Ios Version 15.1
Cisco ≫ Ios Version 15.2
Cisco ≫ Ios Version 15.3
Cisco ≫ Ios Xe Version 3.1.0s
Cisco ≫ Ios Xe Version 3.1.1s
Cisco ≫ Ios Xe Version 3.1.2s
Cisco ≫ Ios Xe Version 3.1.3s
Cisco ≫ Ios Xe Version 3.1.4s
Cisco ≫ Ios Xe Version 3.2.0s
Cisco ≫ Ios Xe Version 3.2.1s
Cisco ≫ Ios Xe Version 3.2.2s
Cisco ≫ Ios Xe Version 3.3.0s
Cisco ≫ Ios Xe Version 3.3.1s
Cisco ≫ Ios Xe Version 3.3.2s
Cisco ≫ Ios Xe Version 3.3.3s
Cisco ≫ Ios Xe Version 3.4.0s
Cisco ≫ Ios Xe Version 3.4.1s
Cisco ≫ Ios Xe Version 3.4.2s
Cisco ≫ Ios Xe Version 3.4.3s
Cisco ≫ Ios Xe Version 3.5.0s
Cisco ≫ Ios Xe Version 3.5.1s
Cisco ≫ Ios Xe Version 3.5.2s
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.36% 0.684
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-rsvp
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1143
Vendor Advisory