CVE-2017-6721
published 2017-07-04CVE-2017-6721: A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote…
PriorityP429medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
2.20%
80.5th percentile
A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to restart unexpectedly, causing a denial of service (DoS) condition. More Information: CSCvc57428. Known Affected Releases: 6.3(1). Known Fixed Releases: 6.3(0.143) 6.2(3c)6 6.2(3.22).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services_tcp_fragment | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Wide Area Application Services TCP Fragment Denial of Service Vulnerability
vendor_cisco·2017-06-21·CVSS 5.8
CVE-2017-6721 [MEDIUM] CWE-20 Cisco Wide Area Application Services TCP Fragment Denial of Service Vulnerability
Cisco Wide Area Application Services TCP Fragment Denial of Service Vulnerability
A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to restart unexpectedly, causing a denial of service (DoS) condition.
The vulnerability is due to incomplete input validation of TCP packets when a packet chain is fragmented. An attacker could exploit this vulnerability by sending a crafted set of TCP fragments through an affected device. An exploit could allow the attacker to cause a DoS condition due to a process restarting unexpectedly. The WAAS could drop traffic during the brief time that the WAASNET process is restarting.
There are no workarounds that address t
Cisco
Cisco Wide Area Application Services TCP Fragment Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6721 Cisco Wide Area Application Services TCP Fragment Denial of Service Vulnerability
CVE-2017-6721: Cisco Wide Area Application Services TCP Fragment Denial of Service Vulnerability
A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to restart unexpectedly, causing a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of TCP packets when a packet chain is fragmented. An attacker could exploit this vulnerability by sending a crafted set of TCP fragments through an affected device. An exploit could allow the attacker to cause a DoS condition due to a process restarting unexpectedly. The WAAS could drop traffic during the brief time that the WAASNET process is restarting. There are no
CVSS: 3.0
CWE:
GHSA
GHSA-w93q-4q5r-8jfj: A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, rem
ghsa_unreviewed·2022-05-17
CVE-2017-6721 [MEDIUM] CWE-20 GHSA-w93q-4q5r-8jfj: A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, rem
A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to restart unexpectedly, causing a denial of service (DoS) condition. More Information: CSCvc57428. Known Affected Releases: 6.3(1). Known Fixed Releases: 6.3(0.143) 6.2(3c)6 6.2(3.22).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99200http://www.securitytracker.com/id/1038747https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-waashttp://www.securityfocus.com/bid/99200http://www.securitytracker.com/id/1038747https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-waas
2017-07-04
Published