CVE-2013-6686: Cisco IOS

Medium severity, CVSS 6.8. EPSS: 1.5% chance of exploitation in the next 30 days.

The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.

Affected products

  • Cisco IOS: up to and including 15.3; version 15.0 only; version 15.0(1)se only; version 15.1 only; version 15.2 only

Published 2013-11-18. Last modified 2026-06-17.