Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2013-5552 Details
Description
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5552 | CVE | Vendor Advisory |
| http://tools.cisco.com/security/center/viewAlert.x?alertId=31715 | CVE | Vendor Advisory |
| http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5552 | [email protected] | Vendor Advisory |
| http://tools.cisco.com/security/center/viewAlert.x?alertId=31715 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-264 | Permissions, Privileges, and Access Controls | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios | <= 12.4\(24\)mdb14 12.4(24)md 12.4(24)md1 12.4(24)md2 12.4(24)md3 12.4(24)md4 12.4(24)md5 12.4(24)md5a 12.4(24)md6 12.4(24)md7 12.4(24)md8 12.4(24)md9 12.4(24)mda6 12.4(24)mda7 12.4(24)mda8 12.4(24)mda9 12.4(24)mda10 12.4(24)mda11 12.4(24)mda12 12.4(24)mda13 12.4(24)mdb10 12.4(24)mdb11 12.4(24)mdb12 12.4(24)mdb13 12.4mda12 |
CPE
Remediation
| |
| cisco content services gateway | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 13, 2013 | Initial Analysis | [email protected] |