CVE-2013-3436

Cisco IOS - Encryption Policy Bypass via UDP Port 848

Title source: llm
STIX 2.1

Description

The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic flow, which allows remote attackers to bypass the encryption policy via certain uses of UDP port 848, aka Bug ID CSCui07698.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/95460
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/85868
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/61362
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1028810

Scores

EPSS 0.0143
EPSS Percentile 70.2%

Details

CWE
CWE-264
Status published
Products (1)
cisco/ios
Published Jul 19, 2013
Tracked Since Feb 18, 2026