CVE-2013-0149

Cisco IOS 12.0-12.4 and 15.0-15.3 - Denial of Service via OSPF LSA Type 1 Packet Validation

Title source: llm
STIX 2.1

Description

The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a (1) unicast or (2) multicast packet, aka Bug IDs CSCug34485, CSCug34469, CSCug39762, CSCug63304, and CSCug39795.

References (2)

Core 2
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/229804

Scores

EPSS 0.0248
EPSS Percentile 82.9%

Details

Status published
Products (50)
cisco/asa_5500 7.0
cisco/asa_5500 7.1
cisco/asa_5500 7.2
cisco/asa_5500 8.0
cisco/asa_5500 8.1
cisco/asa_5500 8.2
cisco/asa_5500 9.0
cisco/asa_5500 9.1
cisco/fwsm
cisco/ios 12.0
... and 40 more
Published Aug 05, 2013
Tracked Since Feb 18, 2026