CVE-2013-5552
Summary
| CVE | CVE-2013-5552 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-11-13 15:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Content Services Gateway | - | All | All | All |
| Operating System | Cisco | Ios | 12.4mda12 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md1 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md2 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md3 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md4 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md5 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md5a | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md6 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md7 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md8 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)md9 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mda10 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mda11 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mda12 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mda13 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mda6 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mda7 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mda8 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mda9 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mdb10 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mdb11 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mdb12 | All | All | All |
| Operating System | Cisco | Ios | 12.4\(24\)mdb13 | All | All | All |
| Operating System | Cisco | Ios | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Alert Details - Security Center - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco Security Notice: Cisco Content Services Gateway Traffic Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.