CVE-2013-1136: Cisco IOS

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

The crypto engine process in Cisco IOS on Aggregation Services Router (ASR) Route Processor 2 does not properly manage memory, which allows local users to cause a denial of service (route processor crash) by creating multiple tunnels and then examining encryption statistics, aka Bug ID CSCuc52193.

Affected products

  • Cisco IOS: affected versions not specified

Published 2013-05-13. Last modified 2026-06-16.