CVE-2013-6692: Cisco IOS XE

Medium severity, CVSS 6.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Cisco IOS XE 3.8S(.2) and earlier does not properly use a DHCP pool during assignment of an IP address, which allows remote authenticated users to cause a denial of service (device reload) via an AAA packet that triggers an address requirement, aka Bug ID CSCuh04949.

Affected products

  • Cisco IOS XE: up to and including 3.8s\(.2\); version 3.7.0s only; version 3.7.1s only; version 3.7.2s only; version 3.8.0s only; version 3.8s(.0) only; …

Published 2013-11-22. Last modified 2026-06-17.