
=====================================================================

                           CERT-Renater

               Note d'Information No. 2013/VULN489
_____________________________________________________________________

DATE                : 31/10/2013

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Cisco IOS XE Software for 1000 Series Aggregation
                                      Services Routers.

======================================================================
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131030-asr1000
______________________________________________________________________

Cisco Security Advisory: Multiple Vulnerabilities in Cisco IOS XE
Software for 1000 Series Aggregation Services Routers

Advisory ID: cisco-sa-20131030-asr1000

Revision 1.0

For Public Release 2013 October 30 16:00  UTC (GMT)

+---------------------------------------------------------------------

Summary
=======

Cisco IOS XE Software for 1000 Series Aggregation Services Routers
(ASR) contains the following denial of service (DoS) vulnerabilities:

    Cisco IOS XE Software Malformed ICMP Packet Denial of Service
      Vulnerability
    Cisco IOS XE Software PPTP Traffic Denial of Service Vulnerability
    Cisco IOS XE Software TCP Segment Reassembly Denial of Service
      Vulnerability
    Cisco IOS XE Software Malformed EoGRE Packet Denial of Service
      Vulnerability

These vulnerabilities are independent of each other; a release that is
affected by one of the vulnerabilities may not be affected by the
others.

Successful exploitation of any of these vulnerabilities could allow an
unauthenticated remote attacker to trigger a reload of the embedded
services processors (ESP) card or the route processor (RP) card,
causing an interruption of services.

Repeated exploitation could result in a sustained DoS condition.

Note: Cisco IOS Software and Cisco IOS-XR Software are not affected by
these vulnerabilities.

Cisco has released free software updates that address these
vulnerabilities. This advisory is available at the following link:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131030-asr1000


=========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================
