CVE-2013-6704: Cisco IOS XE

High severity, CVSS 7.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Cisco IOS XE does not properly manage memory for TFTP UDP flows, which allows remote attackers to cause a denial of service (memory consumption) via TFTP (1) client or (2) server traffic, aka Bug IDs CSCuh09324 and CSCty42686.

Affected products

  • Cisco IOS XE: affected versions not specified

Published 2013-12-03. Last modified 2026-06-17.