CVE-2013-3464

Description

Cisco IOS XR allows local users to cause a denial of service (Silicon Packet Processor memory corruption, improper mutex handling, and device reload) by starting an outbound flood of large ICMP Echo Request packets and stopping this with a CTRL-C sequence, aka Bug ID CSCui60347.

Risk Information

Base Score
6.2
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.13

Associated Vulnerability

VulnerabilityOS Platform
Cisco IOS XR Internet Control Message Protocol Denial of Service Vulnerability For Cisco IOS XR SoftwareNCM
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2013-3464)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705733Security Update for Cisco IOS XR Software 4.0.3.8-tm

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234