CVE-2017-6612
Summary
| CVE | CVE-2017-6612 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-07-25 19:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information: CSCvc67927. |
Risk And Classification
Primary CVSS: v3.0 8.6 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Problem Types: CWE-119 | Redirect Vulnerability
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 8.6 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Asr 5000 Series Software | 17.3.9.62033 | All | All | All |
| Application | Cisco | Asr 5000 Series Software | 17.7.5 | All | All | All |
| Application | Cisco | Asr 5000 Series Software | 19.6.3 | All | All | All |
| Application | Cisco | Asr 5000 Series Software | 20.1.2 | All | All | All |
| Application | Cisco | Asr 5000 Series Software | 20.2.12 | All | All | All |
| Application | Cisco | Asr 5000 Series Software | 21.0.1 | All | All | All |
| Application | Cisco | Asr 5000 Series Software | 21.1.2 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Cisco ASR 5000 Series Aggregation Services Routers | affected Cisco ASR 5000 Series Aggregation Services Routers | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco ASR 5000 Series Aggregation Services Routers GGSN Gateway Redirect Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco ASR 5000 Series GGSN Gateway CVE-2017-6612 HTTP Redirection Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco ASR 5000 Series Router Packet Validation Flaw in Gateway GPRS Support Lets Remote Users Redirect Traffic - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.