CVE-2017-6612
published 2017-07-25CVE-2017-6612: A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an…
PriorityP351high8.6CVSS 3.0
AVNACLPRNUINSCCNIHAN
EPSS
1.90%
77.2th percentile
A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information: CSCvc67927.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asr_5000_series_aggregation_services_routers_ggsn_gateway_redirect | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ASR 5000 Series Aggregation Services Routers GGSN Gateway Redirect Vulnerability
vendor_cisco·2017-07-19·CVSS 5.8
CVE-2017-6612 [MEDIUM] CWE-119 Cisco ASR 5000 Series Aggregation Services Routers GGSN Gateway Redirect Vulnerability
Cisco ASR 5000 Series Aggregation Services Routers GGSN Gateway Redirect Vulnerability
A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device.
The vulnerability exists because the affected device does not sufficiently validate HTTP traffic that contains one or more packets with additional bytes at the end of the packet. An attacker could exploit this vulnerability by changing the properties of a payload in HTTP traffic that is sent to an affected device. A successful exploit could allow the attacker to pipeline requests through an affected device without verifying and accounting for the requests.
There are no workarounds that address
Cisco
Cisco ASR 5000 Series Aggregation Services Routers GGSN Gateway Redirect Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6612 Cisco ASR 5000 Series Aggregation Services Routers GGSN Gateway Redirect Vulnerability
CVE-2017-6612: Cisco ASR 5000 Series Aggregation Services Routers GGSN Gateway Redirect Vulnerability
A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. The vulnerability exists because the affected device does not sufficiently validate HTTP traffic that contains one or more packets with additional bytes at the end of the packet. An attacker could exploit this vulnerability by changing the properties of a payload in HTTP traffic that is sent to an affected device. A successful exploit could allow the attacker to pipeline requests through an affected device without verifying and accounting for the requests. There are no
CVSS: 3.0
CWE
GHSA
GHSA-8559-f4g5-6pjj: A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17
ghsa_unreviewed·2022-05-17
CVE-2017-6612 [HIGH] CWE-119 GHSA-8559-f4g5-6pjj: A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17
A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information: CSCvc67927.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99920http://www.securitytracker.com/id/1038961https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-asrhttp://www.securityfocus.com/bid/99920http://www.securitytracker.com/id/1038961https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-asr
2017-07-25
Published