{"api_version":"1","generated_at":"2026-07-23T08:34:16+00:00","cve":"CVE-2013-3436","urls":{"html":"https://cve.report/CVE-2013-3436","api":"https://cve.report/api/cve/CVE-2013-3436.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-3436","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-3436"},"summary":{"title":"CVE-2013-3436","description":"The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic flow, which allows remote attackers to bypass the encryption policy via certain uses of UDP port 848, aka Bug ID CSCui07698.","state":"PUBLISHED","assigner":"cisco","published_at":"2013-07-19 14:36:13","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3436","name":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3436","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Security Notice: Cisco IOS GET VPN Encryption Policy Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/95460","name":"http://osvdb.org/95460","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=30140","name":"http://tools.cisco.com/security/center/viewAlert.x?alertId=30140","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco IOS GET VPN Encryption Policy Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1028810","name":"http://www.securitytracker.com/id/1028810","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco IOS Group Encrypted Transport VPN Bug Lets Remote Users Bypass Encryption Policy - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85868","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85868","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/61362","name":"http://www.securityfocus.com/bid/61362","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco IOS GET VPN Encryption Policy CVE-2013-3436 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-3436","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-3436","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"3436","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"ios","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T16:07:38.006Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20130718 Cisco IOS GET VPN Encryption Policy Bypass Vulnerability","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3436"},{"name":"95460","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/95460"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=30140"},{"name":"ciscoios-cve20133436-sec-bypass(85868)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85868"},{"name":"61362","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/61362"},{"name":"1028810","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1028810"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-07-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic flow, which allows remote attackers to bypass the encryption policy via certain uses of UDP port 848, aka Bug ID CSCui07698."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-28T15:57:01.000Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"name":"20130718 Cisco IOS GET VPN Encryption Policy Bypass Vulnerability","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3436"},{"name":"95460","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/95460"},{"tags":["x_refsource_CONFIRM"],"url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=30140"},{"name":"ciscoios-cve20133436-sec-bypass(85868)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85868"},{"name":"61362","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/61362"},{"name":"1028810","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1028810"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@cisco.com","ID":"CVE-2013-3436","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic flow, which allows remote attackers to bypass the encryption policy via certain uses of UDP port 848, aka Bug ID CSCui07698."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20130718 Cisco IOS GET VPN Encryption Policy Bypass Vulnerability","refsource":"CISCO","url":"http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3436"},{"name":"95460","refsource":"OSVDB","url":"http://osvdb.org/95460"},{"name":"http://tools.cisco.com/security/center/viewAlert.x?alertId=30140","refsource":"CONFIRM","url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=30140"},{"name":"ciscoios-cve20133436-sec-bypass(85868)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85868"},{"name":"61362","refsource":"BID","url":"http://www.securityfocus.com/bid/61362"},{"name":"1028810","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1028810"}]}}}},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2013-3436","datePublished":"2013-07-18T22:00:00.000Z","dateReserved":"2013-05-06T00:00:00.000Z","dateUpdated":"2024-08-06T16:07:38.006Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-07-19 14:36:13","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:ios:-:*:*:*:*:*:*:*","matchCriteriaId":"B6230A85-30D2-4934-A8A0-11499B7B09F8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"3436","Ordinal":"1","Title":"CVE-2013-3436","CVE":"CVE-2013-3436","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"3436","Ordinal":"1","NoteData":"The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic flow, which allows remote attackers to bypass the encryption policy via certain uses of UDP port 848, aka Bug ID CSCui07698.","Type":"Description","Title":"CVE-2013-3436"},{"CveYear":"2013","CveId":"3436","Ordinal":"2","NoteData":"2013-07-18","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"3436","Ordinal":"3","NoteData":"2017-11-28","Type":"Other","Title":"Modified"}]}}}