Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-3867


A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implementation of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to bypass the access control list (ACL) for specific TCP and UDP traffic. More Information: CSCvc68229. Known Affected Releases: 9.6(2). Known Fixed Releases: 99.1(20.1) 99.1(10.2) 98.1(12.7) 98.1(1.49) 97.1(6.58) 97.1(0.134) 96.2(0.109) 9.7(1.1) 9.6(2.99) 9.6(2.8).


Published

2017-03-17T22:59:00.267

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco adaptive_security_appliance_software 6.3.1 Yes
Operating System cisco adaptive_security_appliance_software 9.6.2 Yes
Operating System cisco adaptive_security_appliance_software 9.6.2.1 Yes
Operating System cisco adaptive_security_appliance_software 9.6.2.2 Yes
Operating System cisco adaptive_security_appliance_software 9.6.2.3 Yes
Operating System cisco adaptive_security_appliance_software 9.6.2.7 Yes
Operating System cisco adaptive_security_appliance_software 9.6.2.8 Yes
Operating System cisco adaptive_security_appliance_software 9.6.2.9 Yes
Operating System cisco adaptive_security_appliance_software 9.6.3 Yes
Operating System cisco adaptive_security_appliance_software - No

References