CVE-2013-5545: Cisco Asr 1001
High severity, CVSS 7.8. EPSS: 1.9% chance of exploitation in the next 30 days.
The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936.
Affected products
- Cisco Asr 1001
- Cisco Asr 1002
- Cisco Asr 1002-X
- Cisco Asr 1004
- Cisco Asr 1006
- Cisco Asr 1023 Router
- Cisco IOS XE: version 3.9.0s only; version 3.9.1s only
Published 2013-10-31. Last modified 2026-06-16.