Lucene search

K
cveCiscoCVE-2017-3865
HistoryJul 04, 2017 - 12:29 a.m.

CVE-2017-3865

2017-07-0400:29:00
cisco
web.nvd.nist.gov
28
security
vulnerability
cisco
staros
asr 5000 series
routers
ipsec
denial of service
dos
nvd
cve-2017-3865

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

53.3%

A vulnerability in the IPsec component of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from establishing, resulting in a denial of service (DoS) condition. Affected Products: ASR 5000 Series Routers, Virtualized Packet Core (VPC) Software. More Information: CSCvc21129. Known Affected Releases: 21.1.0 21.1.M0.65601 21.1.v0. Known Fixed Releases: 21.2.A0.65754 21.1.b0.66164 21.1.V0.66014 21.1.R0.65759 21.1.M0.65749 21.1.0.66030 21.1.0.

Affected configurations

Nvd
Node
ciscostarosMatch21.0.0
OR
ciscostarosMatch21.0_m0.64246
OR
ciscostarosMatch21.0_m0.64702
VendorProductVersionCPE
ciscostaros21.0.0cpe:2.3:o:cisco:staros:21.0.0:*:*:*:*:*:*:*
ciscostaros21.0_m0.64246cpe:2.3:o:cisco:staros:21.0_m0.64246:*:*:*:*:*:*:*
ciscostaros21.0_m0.64702cpe:2.3:o:cisco:staros:21.0_m0.64702:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco StarOS for ASR 5000 Series Routers",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco StarOS for ASR 5000 Series Routers"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

53.3%

Related for CVE-2017-3865