CVE Feed

    Dashboard / CVE / CVE-2013-0149

    CVE-2013-0149

    The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a (1) unicast or (2) multicast packet, aka Bug IDs CSCug34485, CSCug34469, CSCug39762, CSCug63304, and CSCug39795.

    Published:Aug 1, 2013
    Last Modified:Apr 11, 2025
    EPS:Aug 3, 2013
    EPSS Score:0.00937
    CVSS Score:5.8

    Affected Products

    Vendor
    Cisco
    Product
    Asa 5500
    Vendor
    Cisco
    Product
    Fwsm
    Vendor
    Cisco
    Product
    Ios
    Vendor
    Cisco
    Product
    Ios Xe
    Vendor
    Cisco
    Product
    Nx-os
    Vendor
    Cisco
    Product
    Pix Firewall Software
    Vendor
    Cisco
    Product
    Staros

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High