MEDIUM · 6.4

CVE-2013-5552

Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restric...

Vulnerability Description

Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CiscoIos<= 12.4\(24\)mdb14
CiscoContent Services Gateway-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-5552?

CVE-2013-5552 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restric...

How severe is CVE-2013-5552?

CVE-2013-5552 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-5552?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco Content Services Gateway.