CVE-2017-6729

high-risk
Published 2017-07-10

A vulnerability in the Border Gateway Protocol (BGP) processing functionality of the Cisco StarOS operating system for Cisco ASR 5000 Series Routers and Cisco Virtualized Packet Core (VPC) Software could allow an unauthenticated, remote attacker to cause the BGP process on an affected system to reload, resulting in a denial of service (DoS) condition. This vulnerability affects the following products if they are running the Cisco StarOS operating system and BGP is enabled for the system: Cisco ASR 5000 Series Routers and Cisco Virtualized Packet Core Software. More Information: CSCvc44968. Known Affected Releases: 16.4.1 19.1.0 21.1.0 21.1.M0.65824. Known Fixed Releases: 21.3.A0.65902 21.2.A0.65905 21.1.b0.66164 21.1.V0.66014 21.1.R0.65898 21.1.M0.65894 21.1.0.66030 21.1.0.

Do I need to act?

~
1.4% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (20)

Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software

Affected Vendors

56
/ 100
high-risk
Severity 26/34 · High
Exploitability 4/34 · Minimal
Exposure 26/34 · High