Vulnerabilities > CVE-2013-1204 - Resource Management Errors vulnerability in Cisco IOS XR

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
cisco
CWE-399

Summary

Memory leak in the SNMP process in Cisco IOS XR allows remote attackers to cause a denial of service (memory consumption or process reload) by sending many port-162 UDP packets, aka Bug ID CSCug80345.

Vulnerable Configurations

Part Description Count
OS
Cisco
1

Common Weakness Enumeration (CWE)

Seebug

bulletinFamilyexploit
descriptionBUGTRAQ ID: 60153 CVE(CAN) ID: CVE-2013-1204 Cisco IOS是多数思科系统路由器和网络交换机上使用的互联网络操作系统。 Cisco IOS XR在SNMP进程中存在安全漏洞,可使未经身份验证的远程攻击者重新加载受影响进程并泄露部分内存信息。此漏洞源于没有释放已经分配的内存。攻击者通过发送大量的UDP报文到SNMP端口162上可触发此漏洞。 0 Cisco IOS XR 厂商补丁: Cisco ----- Cisco已经为此发布了一个安全公告(CVE-2013-1204)以及相应补丁: CVE-2013-1204:Cisco IOS XR Software SNMP Denial of Service Vulnerability 链接:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1204
idSSV:60810
last seen2017-11-19
modified2013-05-30
published2013-05-30
reporterRoot
titleCisco IOS XR Software SNMP拒绝服务漏洞