CVE-2017-6610 (CNNVD-201704-1061)

HIGH
中文标题:
多款Cisco产品Cisco ASA Software 资源管理错误漏洞
英文标题:
A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software coul...
CVSS分数: 7.7
发布时间: 2017-04-20 22:00:00
漏洞类型: 输入验证错误
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

Cisco ASA 1000V Cloud Firewall等都是美国思科(Cisco)公司的产品。Cisco ASA 1000V Cloud Firewall是一套云防火墙解决方案;Cisco ASA 5500 Series Adaptive Security Appliances是一个下一代防火墙安全设备。Cisco ASA Software是使用在其中的一套防火墙和网络安全软件。 多款Cisco产品中的Cisco ASA Software的Internet Key Exchange Version 1 (IKEv1) XAUTH代码存在拒绝服务漏洞。远程攻击者可通过发送特制的参数利用该漏洞造成受影响系统重载,导致拒绝服务。以下产品受到影响:Cisco ASA 1000V Cloud Firewall;Cisco ASA 5500 Series Adaptive Security Appliances;Cisco ASA 5500-X Series Next-Generation Firewalls;Cisco ASA Services Module for Cisco Catalyst 6500 Series Switches和Cisco 7600 Series Routers;Cisco Adaptive Security Virtual Appliance (ASAv);Cisco ASA for Firepower 9300 Series;Cisco ISA 3000 Industrial Security Appliance。

英文描述:

A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of an affected system. The vulnerability is due to insufficient validation of the IKEv1 XAUTH parameters passed during an IKEv1 negotiation. An attacker could exploit this vulnerability by sending crafted parameters. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability only affects systems configured in routed firewall mode and in single or multiple context mode. This vulnerability can be triggered by IPv4 or IPv6 traffic. A valid IKEv1 Phase 1 needs to be established to exploit this vulnerability, which means that an attacker would need to have knowledge of a pre-shared key or have a valid certificate for phase 1 authentication. This vulnerability affects Cisco ASA Software running on the following products: Cisco ASA 1000V Cloud Firewall, Cisco ASA 5500 Series Adaptive Security Appliances, Cisco ASA 5500-X Series Next-Generation Firewalls, Cisco ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Cisco Adaptive Security Virtual Appliance (ASAv), Cisco ASA for Firepower 9300 Series, Cisco ISA 3000 Industrial Security Appliance. Fixed versions: 9.1(7.7) 9.2(4.11) 9.4(4) 9.5(3) 9.6(1.5). Cisco Bug IDs: CSCuz11685.

CWE类型:
CWE-20 CWE-399
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
cisco adaptive_security_appliance_software 9.0.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.2.10 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.2.10:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.3:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.3.6 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.3.6:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.3.8 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.3.8:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.5 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.5:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.7 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.7:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.17 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.17:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.20 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.20:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.24 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.24:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.26 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.26:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.29 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.29:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.33 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.33:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.35 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.35:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.37 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.37:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.40 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.40:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.0.4.42 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.0.4.42:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1\(7\)4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1\(7\)4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1\(7\)6 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1\(7\)6:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1\(7\)7 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1\(7\)7:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.1.4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.1.4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.2.8 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.2.8:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.3:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.3.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.3.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.4.5 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.4.5:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.5 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.5:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.5.10 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.5.10:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.5.12 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.5.12:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.5.15 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.5.15:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.5.21 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.5.21:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.6 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.6:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.6.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.6.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.6.4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.6.4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.6.6 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.6.6:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.6.8 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.6.8:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.1.6.10 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.1.6.10:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2\(0.0\) - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2\(0.0\):*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2\(0.104\) - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2\(0.104\):*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2\(3.1\) - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2\(3.1\):*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.2.4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.2.4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.2.7 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.2.7:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.2.8 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.2.8:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.3:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.3.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.3.3:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.3.4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.3.4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.4.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.4.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.4.4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.4.4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.4.8 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.4.8:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.2.4.10 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.2.4.10:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3\(1.50\) - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3\(1.50\):*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3\(1.105\) - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3\(1.105\):*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3\(2.100\) - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3\(2.100\):*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3\(2.243\) - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3\(2.243\):*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.1.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.1.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.2.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.2.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.3:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.3.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.3.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.3.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.3.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.3.5 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.3.5:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.3.6 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.3.6:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.3.9 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.3.9:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.3.10 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.3.10:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.3.3.11 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3.3.11:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.0.115 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.0.115:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.1.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.1.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.1.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.1.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.1.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.1.3:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.1.5 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.1.5:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.2.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.2.3:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.3:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.3.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.3.3:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.3.4 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.3.4:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.3.6 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.3.6:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.3.8 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.3.8:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.3.11 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.3.11:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.4.3.12 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.3.12:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.5.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.5.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.5.2 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.5.2:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.5.2.6 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.5.2.6:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.5.2.10 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.5.2.10:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.5.2.14 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.5.2.14:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.6.0 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.6.0:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.6.1 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.6.1:*:*:*:*:*:*:*
cisco adaptive_security_appliance_software 9.6.1.3 - - cpe:2.3:o:cisco:adaptive_security_appliance_software:9.6.1.3:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
97934 vdb-entry
cve.org
访问
1038314 vdb-entry
cve.org
访问
无标题 x_refsource_CONFIRM
cve.org
访问
CVSS评分详情
7.7
HIGH
CVSS向量: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS版本: 3.0
机密性
NONE
完整性
NONE
可用性
HIGH
时间信息
发布时间:
2017-04-20 22:00:00
修改时间:
2024-08-05 15:33:20
创建时间:
2025-11-11 15:34:50
更新时间:
2025-11-11 15:52:57
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2017-6610 2025-11-11 15:19:30 2025-11-11 07:34:50
NVD nvd_CVE-2017-6610 2025-11-11 14:55:27 2025-11-11 07:43:28
CNNVD cnnvd_CNNVD-201704-1061 2025-11-11 15:09:48 2025-11-11 07:52:57
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:52:57
vulnerability_type: 未提取 → 输入验证错误; cnnvd_id: 未提取 → CNNVD-201704-1061; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 输入验证错误
  • cnnvd_id: 未提取 -> CNNVD-201704-1061
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:43:28
severity: SeverityLevel.MEDIUM → SeverityLevel.HIGH; cvss_score: 未提取 → 7.7; cvss_vector: NOT_EXTRACTED → CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H; cvss_version: NOT_EXTRACTED → 3.0; affected_products_count: 0 → 97; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
  • cvss_score: 未提取 -> 7.7
  • cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
  • cvss_version: NOT_EXTRACTED -> 3.0
  • affected_products_count: 0 -> 97
  • data_sources: ['cve'] -> ['cve', 'nvd']