Denial of Service Vulnerability in Cisco ASR 903 and 920 Series Devices
CVE-2017-6603
6.5MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 7 April 2017
Summary
A vulnerability exists in Cisco ASR 903 and ASR 920 Series Devices equipped with an RSP2 card. This flaw stems from improper processing of IPv6 packets, allowing an unauthenticated, adjacent attacker to exploit this weakness and potentially trigger a denial of service condition, thereby impacting the availability of the targeted system. Users of the affected releases should upgrade to fixed versions to mitigate this vulnerability. More details can be found in Cisco's security advisory.
Affected Version(s)
Cisco ASR 903 and ASR 920 Series Devices Cisco ASR 903 and ASR 920 Series Devices
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved