CVE-2017-6607Cisco Adaptive Security Appliance Software vulnerability

CWE-3994 documents4 sources
Severity
8.7HIGHNVD
EPSS
1.0%
top 23.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 20
Latest updateMay 13

Description

A vulnerability in the DNS code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause an affected device to reload or corrupt the information present in the device's local DNS cache. The vulnerability is due to a flaw in handling crafted DNS response messages. An attacker could exploit this vulnerability by triggering a DNS request from the Cisco ASA Software and replying with a crafted response. A successful exploit could cause the device to reload, resulting in a denia

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:HExploitability: 2.2 | Impact: 5.8

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-47rj-rjcp-j4rj: A vulnerability in the DNS code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause an affected device to reload or corrupt2022-05-13
CVEList
CVE-2017-6607: A vulnerability in the DNS code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause an affected device to reload or corrupt2017-04-20

📋Vendor Advisories

1
Cisco
Cisco ASA Software DNS Denial of Service Vulnerability2017-04-19
CVE-2017-6607 — Cisco vulnerability | cvebase