Lucene search

K
cveCiscoCVE-2017-6613
HistoryApr 20, 2017 - 10:59 p.m.

CVE-2017-6613

2017-04-2022:59:00
CWE-20
CWE-399
cisco
web.nvd.nist.gov
28
cisco
prime network registrar
vulnerability
dns
dos
nvd
cve-2017-6613

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

60.4%

A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS process to momentarily restart, which could lead to a partial denial of service (DoS) condition on the affected system. The vulnerability is due to incomplete DNS packet header validation when the packet is received by the application. An attacker could exploit this vulnerability by sending a malformed DNS packet to the application. An exploit could allow the attacker to cause the DNS process to restart, which could lead to a DoS condition. This vulnerability affects Cisco Prime Network Registrar on all software versions prior to 8.3.5. Cisco Bug IDs: CSCvb55412.

Affected configurations

Nvd
Node
ciscoprime_network_registrarMatch8.3.0
OR
ciscoprime_network_registrarMatch8.3.1
OR
ciscoprime_network_registrarMatch8.3.2
OR
ciscoprime_network_registrarMatch8.3.3
OR
ciscoprime_network_registrarMatch8.3.4
VendorProductVersionCPE
ciscoprime_network_registrar8.3.0cpe:2.3:a:cisco:prime_network_registrar:8.3.0:*:*:*:*:*:*:*
ciscoprime_network_registrar8.3.1cpe:2.3:a:cisco:prime_network_registrar:8.3.1:*:*:*:*:*:*:*
ciscoprime_network_registrar8.3.2cpe:2.3:a:cisco:prime_network_registrar:8.3.2:*:*:*:*:*:*:*
ciscoprime_network_registrar8.3.3cpe:2.3:a:cisco:prime_network_registrar:8.3.3:*:*:*:*:*:*:*
ciscoprime_network_registrar8.3.4cpe:2.3:a:cisco:prime_network_registrar:8.3.4:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco Prime Network Registrar",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco Prime Network Registrar"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

60.4%

Related for CVE-2017-6613