Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID CSCul00709.
Conclusion & alert: CVE-2013-6981 is rated Moderate Risk (51.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.03%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.76% | 3.03% | +0.27% |
| 2 | 2026-04-08 | 1.95% | 2.76% | +0.81% |
| 3 | 2026-03-25 | — | 1.95% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.4 | 2.0 | MEDIUM |
|
4.9 | 6.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cisco | ios_xe | <= 3.7s\(.1\) | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* |
| cisco | ios_xe | 2.5\(.0\) | cpe:2.3:o:cisco:ios_xe:2.5\(.0\):*:*:*:*:*:*:* |
| cisco | ios_xe | 2.6\(.0\) | cpe:2.3:o:cisco:ios_xe:2.6\(.0\):*:*:*:*:*:*:* |
| cisco | ios_xe | 2.6\(.1\) | cpe:2.3:o:cisco:ios_xe:2.6\(.1\):*:*:*:*:*:*:* |
| cisco | ios_xe | 2.6\(.2\) | cpe:2.3:o:cisco:ios_xe:2.6\(.2\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.1s\(.0\) | cpe:2.3:o:cisco:ios_xe:3.1s\(.0\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.1s\(.1\) | cpe:2.3:o:cisco:ios_xe:3.1s\(.1\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.1s\(.2\) | cpe:2.3:o:cisco:ios_xe:3.1s\(.2\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.1s\(.3\) | cpe:2.3:o:cisco:ios_xe:3.1s\(.3\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.2s\(.0\) | cpe:2.3:o:cisco:ios_xe:3.2s\(.0\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.2s\(.1\) | cpe:2.3:o:cisco:ios_xe:3.2s\(.1\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.2s\(.2\) | cpe:2.3:o:cisco:ios_xe:3.2s\(.2\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.3s\(.0\) | cpe:2.3:o:cisco:ios_xe:3.3s\(.0\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.3s\(.1\) | cpe:2.3:o:cisco:ios_xe:3.3s\(.1\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.3s\(.2\) | cpe:2.3:o:cisco:ios_xe:3.3s\(.2\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.4s\(.0\) | cpe:2.3:o:cisco:ios_xe:3.4s\(.0\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.4s\(.1\) | cpe:2.3:o:cisco:ios_xe:3.4s\(.1\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.4s\(.2\) | cpe:2.3:o:cisco:ios_xe:3.4s\(.2\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.4s\(.3\) | cpe:2.3:o:cisco:ios_xe:3.4s\(.3\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.4s\(.4\) | cpe:2.3:o:cisco:ios_xe:3.4s\(.4\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.4s\(.5\) | cpe:2.3:o:cisco:ios_xe:3.4s\(.5\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.4s\(.6\) | cpe:2.3:o:cisco:ios_xe:3.4s\(.6\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.5s\(.0\) | cpe:2.3:o:cisco:ios_xe:3.5s\(.0\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.5s\(.1\) | cpe:2.3:o:cisco:ios_xe:3.5s\(.1\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.5s\(.2\) | cpe:2.3:o:cisco:ios_xe:3.5s\(.2\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.6s\(.0\) | cpe:2.3:o:cisco:ios_xe:3.6s\(.0\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.6s\(.1\) | cpe:2.3:o:cisco:ios_xe:3.6s\(.1\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.6s\(.2\) | cpe:2.3:o:cisco:ios_xe:3.6s\(.2\):*:*:*:*:*:*:* |
| cisco | ios_xe | 3.7s\(.0\) | cpe:2.3:o:cisco:ios_xe:3.7s\(.0\):*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://osvdb.org/101423 | |
| http://secunia.com/advisories/56206 | |
| http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6981 | Vendor Advisory |
| http://tools.cisco.com/security/center/viewAlert.x?alertId=32281 | Vendor Advisory |
| http://www.securityfocus.com/bid/64514 | Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1029538 | Third Party Advisory VDB Entry |