CVE Vulnerabilities

CVE-2017-3867

Improper Authentication

Published: Mar 17, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implementation of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to bypass the access control list (ACL) for specific TCP and UDP traffic. More Information: CSCvc68229. Known Affected Releases: 9.6(2). Known Fixed Releases: 99.1(20.1) 99.1(10.2) 98.1(12.7) 98.1(1.49) 97.1(6.58) 97.1(0.134) 96.2(0.109) 9.7(1.1) 9.6(2.99) 9.6(2.8).

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Adaptive_security_appliance_softwareCisco6.3.1 (including)6.3.1 (including)
Adaptive_security_appliance_softwareCisco9.6.2 (including)9.6.2 (including)
Adaptive_security_appliance_softwareCisco9.6.2.1 (including)9.6.2.1 (including)
Adaptive_security_appliance_softwareCisco9.6.2.2 (including)9.6.2.2 (including)
Adaptive_security_appliance_softwareCisco9.6.2.3 (including)9.6.2.3 (including)
Adaptive_security_appliance_softwareCisco9.6.2.7 (including)9.6.2.7 (including)
Adaptive_security_appliance_softwareCisco9.6.2.8 (including)9.6.2.8 (including)
Adaptive_security_appliance_softwareCisco9.6.2.9 (including)9.6.2.9 (including)
Adaptive_security_appliance_softwareCisco9.6.3 (including)9.6.3 (including)

Potential Mitigations

References