CVE-2013-5552

Cisco IOS < 12.4(24)MDB14 - Unauthenticated Access Restriction Bypass via Crafted Packet Series

Title source: llm
STIX 2.1

Description

Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.

References (2)

Core 2
Core References

Scores

EPSS 0.0118
EPSS Percentile 64.3%

Details

CWE
CWE-264
Status published
Products (26)
cisco/content_services_gateway
cisco/ios 12.4\(24\)md
cisco/ios 12.4\(24\)md1
cisco/ios 12.4\(24\)md2
cisco/ios 12.4\(24\)md3
cisco/ios 12.4\(24\)md4
cisco/ios 12.4\(24\)md5
cisco/ios 12.4\(24\)md5a
cisco/ios 12.4\(24\)md6
cisco/ios 12.4\(24\)md7
... and 16 more
Published Nov 13, 2013
Tracked Since Feb 18, 2026