CVE-2017-7408: Input Validation
Published Apr 14, 2017
·Updated
Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.
Affected Software
1 affected component
paloaltonetworks Traps<=3.4.3
Event History
Apr 14, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7408?
CVE-2017-7408 has a medium severity level as it allows for denial of service.
2
How do I fix CVE-2017-7408?
To fix CVE-2017-7408, upgrade the Palo Alto Networks Traps ESM Console to version 3.4.4 or later.
3
What types of attacks are possible with CVE-2017-7408?
CVE-2017-7408 may allow attackers to exploit improper validation to cause a denial of service.
4
Which versions are affected by CVE-2017-7408?
Versions of Palo Alto Networks Traps ESM Console prior to 3.4.4 are affected by CVE-2017-7408.
5
Is CVE-2017-7408 specific to certain operating systems?
CVE-2017-7408 is not specific to any operating system but affects the Traps application itself.