CVE-2017-6610 — Improper Input Validation in Cisco Adaptive Security Appliance Software
Severity
7.7HIGHNVD
EPSS
0.6%
top 29.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 20
Latest updateMay 13
Description
A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of an affected system. The vulnerability is due to insufficient validation of the IKEv1 XAUTH parameters passed during an IKEv1 negotiation. An attacker could exploit this vulnerability by sending crafted parameters. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability only affec…
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 3.1 | Impact: 4.0
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-786p-2rc4-pc65: A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause↗2022-05-13
CVEList▶
CVE-2017-6610: A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause↗2017-04-20
📋Vendor Advisories
1Cisco
▶