5
CVSSv2

CVE-2017-6672

Published: 25/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers up to and including 21.x could allow an unauthenticated, remote malicious user to bypass ACL rules that have been configured for an affected device. More Information: CSCvb99022 CSCvc16964 CSCvc37351 CSCvc54843 CSCvc63444 CSCvc77815 CSCvc88658 CSCve08955 CSCve14141 CSCve33870.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco asr 5000 series software 19.3.12

cisco asr 5000 series software 19.6.3

cisco asr 5000 series software 20.1.v5

cisco asr 5000 series software 20.2.12

cisco asr 5000 series software 21.1.m0.65931

cisco asr 5000 series software 21.1.m0.65986

cisco asr 5000 series software 21.2.a0.65995

cisco asr 5000 series software 21.1.m0.65921

cisco asr 5000 series software 19.3.11

cisco asr 5000 series software 19.3.5

cisco asr 5000 series software 19.6.0

cisco asr 5000 series software 20.3.0

cisco asr 5000 series software 21.0.v2

cisco asr 5000 series software 21.1.v0

cisco asr 5000 series software 21.1.0

cisco asr 5000 series software 20.3.1

cisco asr 5000 series software 21.2.a0.65914

cisco asr 5000 series software 20.2.4

cisco asr 5000 series software 21.1.2

cisco asr 5000 series software 21.3.0

cisco asr 5000 series software 21.0.v1.66638

cisco asr 5000 series software 19.6.6

cisco asr 5000 series software 21.1.m0.65710

Vendor Advisories

A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass ACL rules that have been configured for an affected device The vulnerability exists because the affected device fails to inspect and match certain traffic t ...