Vulnerability Description
The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritize health pings, which allows remote attackers to cause a denial of service (watchdog timeout and TNC reset) via a flood of network traffic, aka Bug ID CSCud97155.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Ons 15454 System Software | 9.0 |
| Cisco | Ons 15454 Mspp | All versions |
| Cisco | Ons 15454 Mstp | All versions |
| Cisco | Ons 15454E Optical Transport Platform | All versions |
| Cisco | Ons 15454 | All versions |
| Cisco | Ons 15454 Multiservice Transport Platform | All versions |
| Cisco | Ons 15454 Sdh Multiservice Provisioning Platform | All versions |
| Cisco | Ons 15454 Sonet Multiservice Provisioning Platform | All versions |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6701Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32200Vendor Advisory
- http://www.securitytracker.com/id/1029512Third Party AdvisoryVDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6701Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32200Vendor Advisory
- http://www.securitytracker.com/id/1029512Third Party AdvisoryVDB Entry
FAQ
What is CVE-2013-6701?
CVE-2013-6701 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritize health pings, which allows remote attackers to ca...
How severe is CVE-2013-6701?
CVE-2013-6701 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6701?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Cisco Ons 15454 System Software, Cisco Ons 15454 Mspp, Cisco Ons 15454 Mstp, Cisco Ons 15454E Optical Transport Platform, Cisco Ons 15454.