CVE-2017-7432
published 2017-05-03CVE-2017-7432: Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.
PriorityP346critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.7th percentile
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netiq | imanager | — | — |
| netiq | imanager | — | — |
| netiq | imanager | — | — |
| netiq | imanager | — | — |
| netiq | imanager | — | — |
| netiq | imanager | — | — |
| novell | imanager | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cf72-wpmx-g58x: Novell iManager 2
ghsa_unreviewed·2022-05-13
CVE-2017-7432 [CRITICAL] GHSA-cf72-wpmx-g58x: Novell iManager 2
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.
Cisco
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial of Service Vulnerability
vendor_cisco·2017-11-03·CVSS 6.8
CVE-2017-12319 [MEDIUM] CWE-20 Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial of Service Vulnerability
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial of Service Vulnerability
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.
The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is miscalculated.
Cisco
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12319 Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial of Service Vulnerability
CVE-2017-12319: Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial of Service Vulnerability
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is m
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.novell.com/show_bug.cgi?id=1027619https://dl.netiq.com/Download?buildid=24FxpmqdThE~https://dl.netiq.com/Download?buildid=wpS1UqIlx-o~https://www.netiq.com/support/kb/doc.php?id=7016795https://www.novell.com/support/kb/doc.php?id=7010166https://bugzilla.novell.com/show_bug.cgi?id=1027619https://dl.netiq.com/Download?buildid=24FxpmqdThE~https://dl.netiq.com/Download?buildid=wpS1UqIlx-o~https://www.netiq.com/support/kb/doc.php?id=7016795https://www.novell.com/support/kb/doc.php?id=7010166
2017-05-03
Published