CVE-2017-3826 (CNNVD-201703-021)
中文标题:
Cisco NetFlow Generation Appliance 安全漏洞
英文标题:
A vulnerability in the Stream Control Transmission Protocol (SCTP) decoder of the Cisco NetFlow Gene...
漏洞描述
中文描述:
Cisco NetFlow Generation Appliance(NGA)是美国思科(Cisco)公司的一套可扩展的用于数据中心实现流量可见性的解决方案。该方案提供流量分析和其他需求管理等功能。Stream Control Transmission Protocol(SCTP)decoder是其中的一个流控制传输协议解码器。 Cisco NGA 3140版本、3240版本和3340版本中的SCTP decoder存在拒绝服务漏洞。远程攻击者可通过发送特制的SCTP数据包利用该漏洞造成设备挂起或重载,导致拒绝服务。
英文描述:
A vulnerability in the Stream Control Transmission Protocol (SCTP) decoder of the Cisco NetFlow Generation Appliance (NGA) with software before 1.1(1a) could allow an unauthenticated, remote attacker to cause the device to hang or unexpectedly reload, causing a denial of service (DoS) condition. The vulnerability is due to incomplete validation of SCTP packets being monitored on the NGA data ports. An attacker could exploit this vulnerability by sending malformed SCTP packets on a network that is monitored by an NGA data port. SCTP packets addressed to the IP address of the NGA itself will not trigger this vulnerability. An exploit could allow the attacker to cause the appliance to become unresponsive or reload, causing a DoS condition. User interaction could be needed to recover the device using the reboot command from the CLI. The following Cisco NetFlow Generation Appliances are vulnerable: NGA 3140, NGA 3240, NGA 3340. Cisco Bug IDs: CSCvc83320.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | netflow_generation_appliance_software | 1.0\(2\) | - | - |
cpe:2.3:o:cisco:netflow_generation_appliance_software:1.0\(2\):*:*:*:*:*:*:*
|
| cisco | netflow_generation_appliance_software | 1.0.0 | - | - |
cpe:2.3:o:cisco:netflow_generation_appliance_software:1.0.0:*:*:*:*:*:*:*
|
| cisco | netflow_generation_appliance_software | 1.1\(1\) | - | - |
cpe:2.3:o:cisco:netflow_generation_appliance_software:1.1\(1\):*:*:*:*:*:*:*
|
| cisco | netflow_generation_appliance_software | 1.1.0 | - | - |
cpe:2.3:o:cisco:netflow_generation_appliance_software:1.1.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-3826 |
2025-11-11 15:19:27 | 2025-11-11 07:34:47 |
| NVD | nvd_CVE-2017-3826 |
2025-11-11 14:55:26 | 2025-11-11 07:43:24 |
| CNNVD | cnnvd_CNNVD-201703-021 |
2025-11-11 15:09:46 | 2025-11-11 07:52:55 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-201703-021
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']