Vulnerability Bulletins

Cisco IOS Software Resource Reservation Protocol Interface Queue Wedge Vulnerability


System information

   
Affected software Cisco

Description

A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger an interface queue wedge on the affected device.The vulnerability is due to improper parsing of UDP RSVP packets. An attacker could exploit this vulnerability by sending UDP port 1698 RSVP packets to the vulnerable device. An exploit could cause Cisco IOS Software and Cisco IOS XE Software to incorrectly process incoming

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130925-rsvp?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20IOS%20Software%20Resource%20Reservation%20Protocol%20Interface%20Queu

Standar resources

Property Value
CVE CVE-2013-5478.

Version history

Version Comments Date
1.0 Advisory issued 2014-03-13
Ministerio de Defensa
CNI
CCN
CCN-CERT