CVE-2017-6603: Medium severity Cisco Asr 900 Series Firmware vulnerability
A vulnerability in Cisco ASR 903 or ASR 920 Series Devices running with an RSP2 card could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on a targeted system because of incorrect IPv6 Packet Processing. More Information: CSCuy94366. Known Affected Releases: 15.4(3)S3.15. Known Fixed Releases: 15.6(2)SP 15.6(1.31)SP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco ASR 903/ASR 920 Series Devices (RSP2)to a version that resolves this vulnerability.Fixed in 15.6(2)SP 15.6(1.31)SPPatch CSCuy94366
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6603?
CVE-2017-6603 is classified as a high severity vulnerability due to its potential to cause a denial of service (DoS) condition.
How do I fix CVE-2017-6603?
To remediate CVE-2017-6603, you should upgrade to a fixed version of the Cisco ASR 900 Series Software that addresses this vulnerability.
Which Cisco devices are affected by CVE-2017-6603?
CVE-2017-6603 specifically affects Cisco ASR 903 and ASR 920 Series Devices running with an RSP2 card.
What is the impact of CVE-2017-6603?
The impact of CVE-2017-6603 is that an unauthenticated, adjacent attacker could trigger a denial of service condition on the vulnerable system.
Is CVE-2017-6603 remote or local access required for exploitation?
CVE-2017-6603 requires adjacent network access by an unauthenticated attacker for exploitation.