CVE-2017-6770 is a vulnerability in the Open Shortest Path First (OSPF) routing protocol affecting Cisco IOS, ASA Software, NX-OS, and IOS XE. An unauthenticated, remote attacker can exploit this by injecting crafted OSPF packets to take full control of the OSPF Autonomous System (AS) domain routing table, leading to traffic interception or black-holing. The CVSS score is 4.2 (Medium), indicating a network-based attack with high complexity, requiring specific LSA database parameters. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1\(0.825a\)CPE matchmatch criteria | cpe:2.3:a:cisco:nx-os:1.1\(0.825a\):*:*:*:*:nexus_9000_series:*:* | ||
1.1\(1g\)CPE matchmatch criteria | cpe:2.3:a:cisco:nx-os:1.1\(1g\):*:*:*:*:nexus_9000_series:*:* | ||
7.3\(1\)n1\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:nx-os_for_nexus_5500_platform_switches:7.3\(1\)n1\(1\):*:*:*:*:*:*:* | ||
baseCPE matchmatch criteria | cpe:2.3:a:cisco:nx-os_for_nexus_5500_platform_switches:base:*:*:*:*:*:*:* | ||
7.3\(1\)n1\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:nx-os_for_nexus_5600_platform_switches:7.3\(1\)n1\(1\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.