CVE-2013-5549: Cisco IOS XR

High severity, CVSS 7.1. EPSS: 1.7% chance of exploitation in the next 30 days.

Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCuh30380.

Affected products

  • Cisco IOS XR: version 3.8.1 only; version 3.8.2 only; version 3.8.3 only; version 3.8.4 only; version 3.9.0 only; version 3.9.1 only; …

Published 2013-10-25. Last modified 2026-06-16.