Vulnerabilities > Cisco > IOS XE > High

DATE CVE VULNERABILITY TITLE RISK
2013-10-31 CVE-2013-5543 Improper Input Validation vulnerability in Cisco products
Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via malformed ICMP error packets associated with a (1) TCP or (2) UDP session that is under inspection by the Zone-Based Firewall (ZBFW) component, aka Bug ID CSCtt26470.
network
low complexity
cisco CWE-20
7.8
2013-09-27 CVE-2013-5478 Improper Input Validation vulnerability in Cisco IOS and IOS XE
Cisco IOS 15.0 through 15.3 and IOS XE 3.2 through 3.8, when a VRF interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via crafted UDP RSVP packets, aka Bug ID CSCuf17023.
network
low complexity
cisco CWE-20
7.8
2013-09-27 CVE-2013-5475 Improper Input Validation vulnerability in Cisco IOS and IOS XE
Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets that are processed locally by a (1) server or (2) relay agent, aka Bug ID CSCug31561.
network
low complexity
cisco CWE-20
7.8
2013-09-27 CVE-2013-5473 Resource Management Errors vulnerability in Cisco IOS and IOS XE
Memory leak in Cisco IOS 12.2, 15.1, and 15.2; IOS XE 3.4.2S through 3.4.5S; and IOS XE 3.6.xS before 3.6.1S allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed IKEv1 packets, aka Bug ID CSCtx66011.
network
low complexity
cisco CWE-399
7.8
2013-09-27 CVE-2013-5472 Improper Input Validation vulnerability in Cisco IOS and IOS XE
The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attackers to cause a denial of service (device reload) by leveraging an MSDP peer relationship, aka Bug ID CSCuc81226.
network
cisco CWE-20
7.1
2013-04-11 CVE-2013-2779 Improper Input Validation vulnerability in Cisco products
Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 MVPN (aka MVPNv6) packets, aka Bug ID CSCub34945, a different vulnerability than CVE-2013-1164.
network
low complexity
cisco CWE-20
7.8
2013-04-11 CVE-2013-1167 Path Traversal vulnerability in Cisco products
Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to cause a denial of service (card reload) via packets that are not properly handled during the processing of encapsulation, aka Bug ID CSCtt11558.
network
cisco CWE-22
7.1
2013-04-11 CVE-2013-1166 Improper Input Validation vulnerability in Cisco products
Cisco IOS XE 3.2 through 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR), when VRF-aware NAT and SIP ALG are enabled, allows remote attackers to cause a denial of service (card reload) by sending many SIP packets, aka Bug ID CSCuc65609.
network
low complexity
cisco CWE-20
7.8
2013-04-11 CVE-2013-1165 Improper Input Validation vulnerability in Cisco products
Cisco IOS XE 2.x and 3.x before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) allows remote attackers to cause a denial of service (card reload) by sending many crafted L2TP packets, aka Bug ID CSCtz23293.
network
low complexity
cisco CWE-20
7.8
2013-04-11 CVE-2013-1164 Unspecified vulnerability in Cisco products
Cisco IOS XE 3.4 before 3.4.4S, 3.5, and 3.6 on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 multicast packets, aka Bug ID CSCtz97563.
network
low complexity
cisco
7.8