CVE-2013-0149
Cisco IOS 12.0-12.4 and 15.0-15.3 - Denial of Service via OSPF LSA Type 1 Packet Validation
Title source: llmDescription
The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a (1) unicast or (2) multicast packet, aka Bug IDs CSCug34485, CSCug34469, CSCug39762, CSCug63304, and CSCug39795.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130801-lsaospf
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/229804
Scores
EPSS
0.0248
EPSS Percentile
82.9%
Details
Status
published
Products (50)
cisco/asa_5500
7.0
cisco/asa_5500
7.1
cisco/asa_5500
7.2
cisco/asa_5500
8.0
cisco/asa_5500
8.1
cisco/asa_5500
8.2
cisco/asa_5500
9.0
cisco/asa_5500
9.1
cisco/fwsm
cisco/ios
12.0
... and 40 more
Published
Aug 05, 2013
Tracked Since
Feb 18, 2026