CVE-2017-4920 is a medium-severity vulnerability affecting VMware NSX-V Edge versions 6.2.x prior to 6.2.8 and 6.3.x prior to 6.3.3. It stems from an improper handling of link-state advertisements (LSAs) within the OSPF protocol implementation. A successful attack, though complex, could lead to a denial-of-service (DoS) by causing continuous LSA loops between routers, resulting in network disruption. There is no evidence of active exploitation, nor is public exploit code available, and community discussion and media coverage are minimal, suggesting a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.0, < 6.2.8CPE matchmatch criteria | cpe:2.3:a:vmware:nsx-v_edge:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.3.3CPE matchmatch criteria | cpe:2.3:a:vmware:nsx-v_edge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.