Release date:
Updated on:
Affected Systems:
Cisco IOS XE
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63855
CVE (CAN) ID: CVE-2013-6692
Cisco IOS is an interconnected network operating system used on most Cisco system routers and network switches.
The DHCP function assigned an IP address to the AAA client on Cisco ios xe Software has a security vulnerability, which can cause authenticated remote attackers to reload the affected device. This vulnerability is caused by the failure to correctly process AAA packets. Attackers exploit this vulnerability by sending AAA packets to devices configured for identity authentication and allocating IP addresses in the DHCP pool.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6692
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2013-6692) and patches for this:
CVE-2013-6692: Cisco ios xe aaa dhcp Denial of Service Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6692