Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6672

Опубликовано: 25 июл. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x could allow an unauthenticated, remote attacker to bypass ACL rules that have been configured for an affected device. More Information: CSCvb99022 CSCvc16964 CSCvc37351 CSCvc54843 CSCvc63444 CSCvc77815 CSCvc88658 CSCve08955 CSCve14141 CSCve33870.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:asr_5000_series_software:19.3.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:19.3.11:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:19.3.12:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:19.6.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:19.6.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:19.6.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:20.1.v5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:20.2.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:20.2.12:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:20.3.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:20.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.0.v1.66638:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.0.v2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.1.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.1.m0.65710:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.1.m0.65921:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.1.m0.65931:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.1.m0.65986:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.1.v0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.2.a0.65914:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.2.a0.65995:*:*:*:*:*:*:*
cpe:2.3:a:cisco:asr_5000_series_software:21.3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00372
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x could allow an unauthenticated, remote attacker to bypass ACL rules that have been configured for an affected device. More Information: CSCvb99022 CSCvc16964 CSCvc37351 CSCvc54843 CSCvc63444 CSCvc77815 CSCvc88658 CSCve08955 CSCve14141 CSCve33870.

EPSS

Процентиль: 58%
0.00372
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-863