OSPF Protocol Vulnerability in Cisco IOS and ASA Software
CVE-2017-6770
4.2MEDIUM
What is CVE-2017-6770?
A vulnerability exists in the Open Shortest Path First (OSPF) Routing Protocol, allowing unauthenticated remote attackers to inject malicious OSPF packets. Successful exploitation enables attackers to manipulate the OSPF Autonomous System's routing table, potentially leading to traffic interception or loss. The vulnerability can only be triggered by sending specially crafted OSPF Link State Advertisement (LSA) type 1 packets, leading to the disruption of normal routing operations. OSPFv3 and Fabric Shortest Path First (FSPF) protocols are not affected by this flaw.
Affected Version(s)
Multiple Cisco Products Multiple Cisco Products