CVE-2017-7177 — Improperly Implemented Security Check for Standard in Suricata
Severity
7.5HIGHNVD
EPSS
0.2%
top 52.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18
Latest updateMay 14
Description
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages2 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2017-7177: suricata - Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack o...↗2017