Asr 1004
Vendor:
First CVE: Apr 11, 2013 · Active for 13 years
14
Total CVEs
More Total CVEs than 92% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Asr 1004 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2013
13 years ago
Most Recent CVE
May 25, 2014
4,447 days ago
CVE Severity & Scoring
Asr 100414 CVEs
36%
64%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown14 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown14 (100.0%)
User Interaction
None0 (0.0%)
Unknown14 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown14 (100.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5547HIGH Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE packets over (1) IPv4 or (2) IPv6 | Oct 31, 2013 | 7.8 | 25 | NO | NO |
CVE-2012-5017MEDIUM Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, a | Apr 23, 2014 | 6.8 | 22 | NO | NO |
CVE-2014-2183MEDIUM The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP pack | Apr 29, 2014 | 6.3 | 21 | NO | NO |
CVE-2012-5723MEDIUM Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) | Apr 24, 2014 | 6.1 | 21 | NO | NO |
CVE-2013-5545HIGH The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets | Oct 31, 2013 | 7.8 | 21 | NO | NO |
CVE-2013-1167HIGH Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to ca | Apr 11, 2013 | 7.1 | 21 | NO | NO |
CVE-2012-1366MEDIUM Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device r | Apr 23, 2014 | 6.1 | 20 | NO | NO |
CVE-2013-5546HIGH The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via larg | Oct 31, 2013 | 7.8 | 20 | NO | NO |
CVE-2013-5543HIGH Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via malformed ICMP error packets assoc | Oct 31, 2013 | 7.8 | 20 | NO | NO |
CVE-2013-2779HIGH Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle El | Apr 11, 2013 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Asr 1004
Top CWEs
Versions
No cataloged versions.