CVE-2017-6610Improper Input Validation in Cisco Adaptive Security Appliance Software

Severity
7.7HIGHNVD
EPSS
0.6%
top 29.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 20
Latest updateMay 13

Description

A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of an affected system. The vulnerability is due to insufficient validation of the IKEv1 XAUTH parameters passed during an IKEv1 negotiation. An attacker could exploit this vulnerability by sending crafted parameters. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability only affec

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 3.1 | Impact: 4.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-786p-2rc4-pc65: A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause2022-05-13
CVEList
CVE-2017-6610: A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause2017-04-20

📋Vendor Advisories

1
Cisco
Cisco ASA Software Internet Key Exchange Version 1 XAUTH Denial of Service Vulnerability2017-04-19
CVE-2017-6610 — Improper Input Validation in Cisco | cvebase