Cisco IOS XR Software Memory Exhaustion Vulnerability (cisco-sa-20131002-iosxr)

high Nessus Plugin ID 71437

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

Cisco IOS XR Software version 4.3.1 contains a vulnerability that could result in complete packet memory exhaustion. Successful exploitation could render critical services on the affected device unable to allocate packets resulting in a denial of service (DoS) condition. Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.

Solution

Apply the relevant patch referenced in Cisco Security Advisory cisco-sa-20131002-iosxr.

See Also

http://www.nessus.org/u?8b21028c

Plugin Details

Severity: High

ID: 71437

File Name: cisco-sa-20131002-iosxr.nasl

Version: 1.7

Type: combined

Family: CISCO

Published: 12/14/2013

Updated: 4/8/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.5

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2013-5503

Vulnerability Information

CPE: cpe:/o:cisco:ios_xr

Required KB Items: Host/Cisco/IOS-XR/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 10/2/2013

Vulnerability Publication Date: 10/2/2013

Reference Information

CVE: CVE-2013-5503

BID: 62770

CISCO-SA: cisco-sa-20131002-iosxr

CISCO-BUG-ID: CSCue69413