Vulnerability Description
The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | <= 15.3 |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6686Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=31757Vendor Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6686Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=31757Vendor Advisory
FAQ
What is CVE-2013-6686?
CVE-2013-6686 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug...
How severe is CVE-2013-6686?
CVE-2013-6686 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6686?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios.