CVE-2013-1148 describes a denial-of-service vulnerability in the IP Service Level Agreement (SLA) feature of Cisco IOS and IOS XE, specifically affecting versions 15.2 and 3.1.xS through 3.7.xS. Remote attackers can trigger a device reload by sending crafted IPv4 or IPv6 IP SLA packets to UDP port 1167. With a CVSS score of 7.8, this vulnerability is considered high severity due to its network-based attack vector, low attack complexity, and complete availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2:*:*:*:*:*:*:* | ||
3.1.0sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.0s:*:*:*:*:*:*:* | ||
3.1.1sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.1s:*:*:*:*:*:*:* | ||
3.1.2sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.2s:*:*:*:*:*:*:* | ||
3.1.3sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.3s:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.