CVE-2017-6625 (CNNVD-201705-205)
中文标题:
Cisco Firepower System Software 安全漏洞
英文标题:
A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of ...
漏洞描述
中文描述:
Cisco Firepower System Software是美国思科(Cisco)公司的一款下一代防火墙产品(NGFW)。 Cisco Firepower System Software中的访问控制策略存在拒绝服务漏洞,该漏洞源于程序没有正确处理SSL策略。远程攻击者可通过发送特制的数据包利用该漏洞造成拒绝服务。
英文描述:
A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access control policy of Cisco Firepower System Software could allow an authenticated, remote attacker to cause an affected system to stop inspecting and processing packets, resulting in a denial of service (DoS) condition. The vulnerability is due to improper SSL policy handling by the affected software when packets are passed through the sensing interfaces of an affected system. An attacker could exploit this vulnerability by sending crafted packets through a targeted system. This vulnerability affects Cisco Firepower System Software that is configured with the SSL policy feature. Cisco Bug IDs: CSCvc84361.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | firepower_threat_defense | 6.0.0 | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:6.0.0:*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | 6.0.1 | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:6.0.1:*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | 6.1.0 | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:6.1.0:*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | 6.1.0.2 | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:6.1.0.2:*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | 6.2.0 | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:6.2.0:*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | 6.2.1 | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:6.2.1:*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | 6.2.2 | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:6.2.2:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-6625 |
2025-11-11 15:19:31 | 2025-11-11 07:34:50 |
| NVD | nvd_CVE-2017-6625 |
2025-11-11 14:55:28 | 2025-11-11 07:43:28 |
| CNNVD | cnnvd_CNNVD-201705-205 |
2025-11-11 15:09:49 | 2025-11-11 07:53:02 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 资源管理错误
- cnnvd_id: 未提取 -> CNNVD-201705-205
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.1
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 7
- data_sources: ['cve'] -> ['cve', 'nvd']