Denial of Service Vulnerability in Cisco ASR 5000 Series Routers
CVE-2017-3865
5.8MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 4 July 2017
Summary
A security flaw within the IPsec component of the Cisco ASR 5000 Series Routers could potentially allow an unauthenticated remote attacker to terminate all active IPsec VPN tunnels. This intervention would also hinder the establishment of new tunnels, resulting in a service disruption. Affected deployments include specific versions of the ASR 5000 Series Routers and Virtualized Packet Core Software. Refer to Cisco's advisory for further details on affected and fixed releases, including known issues and resolutions.
Affected Version(s)
Cisco StarOS for ASR 5000 Series Routers Cisco StarOS for ASR 5000 Series Routers
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved