CVE-2017-3865
Published on: 07/03/2017 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:26:32 PM UTC
Certain versions of Staros from Cisco contain the following vulnerability:
A vulnerability in the IPsec component of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from establishing, resulting in a denial of service (DoS) condition. Affected Products: ASR 5000 Series Routers, Virtualized Packet Core (VPC) Software. More Information: CSCvc21129. Known Affected Releases: 21.1.0 21.1.M0.65601 21.1.v0. Known Fixed Releases: 21.2.A0.65754 21.1.b0.66164 21.1.V0.66014 21.1.R0.65759 21.1.M0.65749 21.1.0.66030 21.1.0.
- CVE-2017-3865 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.8 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | NONE | NONE | LOW |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco StarOS for ASR 5500 Series Routers CVE-2017-3865 Remote Denial of Service Vulnerability | Third Party Advisory VDB Entry cve.report (archive) text/html |
![]() |
Cisco ASR 5000 Series Routers IKE Processing Bug Lets Remote Users Deny Service - SecurityTracker | Third Party Advisory VDB Entry www.securitytracker.com text/html |
![]() |
Cisco StarOS for ASR 5000 Series Routers IPsec VPN Tunnel Denial of Service Vulnerability | Vendor Advisory tools.cisco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Cisco | Staros | 21.0.0 | All | All | All |
Operating System | Cisco | Staros | 21.0_m0.64246 | All | All | All |
Operating System | Cisco | Staros | 21.0_m0.64702 | All | All | All |
Operating System | Cisco | Staros | 21.0.0 | All | All | All |
Operating System | Cisco | Staros | 21.0_m0.64246 | All | All | All |
Operating System | Cisco | Staros | 21.0_m0.64702 | All | All | All |
- cpe:2.3:o:cisco:staros:21.0.0:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:staros:21.0_m0.64246:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:staros:21.0_m0.64702:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:staros:21.0.0:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:staros:21.0_m0.64246:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:staros:21.0_m0.64702:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE