Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-5552


Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.


Published

2013-11-13T15:55:03.767

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios ≤ 12.4\(24\)mdb14 Yes
Operating System cisco ios 12.4\(24\)md Yes
Operating System cisco ios 12.4\(24\)md1 Yes
Operating System cisco ios 12.4\(24\)md2 Yes
Operating System cisco ios 12.4\(24\)md3 Yes
Operating System cisco ios 12.4\(24\)md4 Yes
Operating System cisco ios 12.4\(24\)md5 Yes
Operating System cisco ios 12.4\(24\)md5a Yes
Operating System cisco ios 12.4\(24\)md6 Yes
Operating System cisco ios 12.4\(24\)md7 Yes
Operating System cisco ios 12.4\(24\)md8 Yes
Operating System cisco ios 12.4\(24\)md9 Yes
Operating System cisco ios 12.4\(24\)mda6 Yes
Operating System cisco ios 12.4\(24\)mda7 Yes
Operating System cisco ios 12.4\(24\)mda8 Yes
Operating System cisco ios 12.4\(24\)mda9 Yes
Operating System cisco ios 12.4\(24\)mda10 Yes
Operating System cisco ios 12.4\(24\)mda11 Yes
Operating System cisco ios 12.4\(24\)mda12 Yes
Operating System cisco ios 12.4\(24\)mda13 Yes
Operating System cisco ios 12.4\(24\)mdb10 Yes
Operating System cisco ios 12.4\(24\)mdb11 Yes
Operating System cisco ios 12.4\(24\)mdb12 Yes
Operating System cisco ios 12.4\(24\)mdb13 Yes
Operating System cisco ios 12.4mda12 Yes
Hardware cisco content_services_gateway - Yes

References