CVE Vulnerabilities

CVE-2017-3867

Improper Authentication

Published: Mar 17, 2017 | Modified: Aug 15, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implementation of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to bypass the access control list (ACL) for specific TCP and UDP traffic. More Information: CSCvc68229. Known Affected Releases: 9.6(2). Known Fixed Releases: 99.1(20.1) 99.1(10.2) 98.1(12.7) 98.1(1.49) 97.1(6.58) 97.1(0.134) 96.2(0.109) 9.7(1.1) 9.6(2.99) 9.6(2.8).

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Adaptive_security_appliance_software Cisco 6.3.1 (including) 6.3.1 (including)
Adaptive_security_appliance_software Cisco 9.6.2 (including) 9.6.2 (including)
Adaptive_security_appliance_software Cisco 9.6.2.1 (including) 9.6.2.1 (including)
Adaptive_security_appliance_software Cisco 9.6.2.2 (including) 9.6.2.2 (including)
Adaptive_security_appliance_software Cisco 9.6.2.3 (including) 9.6.2.3 (including)
Adaptive_security_appliance_software Cisco 9.6.2.7 (including) 9.6.2.7 (including)
Adaptive_security_appliance_software Cisco 9.6.2.8 (including) 9.6.2.8 (including)
Adaptive_security_appliance_software Cisco 9.6.2.9 (including) 9.6.2.9 (including)
Adaptive_security_appliance_software Cisco 9.6.3 (including) 9.6.3 (including)

Potential Mitigations

References