imPC@ndo IT

Tracker / CVE-2013-2779

CVE-2013-2779

High 7.8

Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 MVPN (aka MVPNv6) packets, aka Bug ID CSCub34945, a different vulnerability than CVE-2013-1164.

Affected products and versions

cisco asr_1001
cisco asr_1002
cisco asr_1002-x
cisco asr_1002_fixed_router
cisco asr_1004
cisco asr_1006
cisco asr_1013
cisco asr_1023_router
cisco ios_xe

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References