7.5
CVE-2017-7397
- EPSS 11.07%
- Veröffentlicht 03.04.2017 20:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- CVE-Watchlists
- Unerledigt
BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). This product enables net.ipv4.conf.all.log_martians by default. NOTE: the vendor reports "It has been proved that this vulnerability has no foundation and it is totally fake and based on false assumptions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Backbox ≫ Backbox Linux Version4.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 11.07% | 0.954 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
http://www.exploitalert.com/view-details.html?id=26361
https://backbox.org/portal/blog/false-cve-backbox-46-unmasked
https://cxsecurity.com/issue/WLB-2017040001
https://forum.backbox.org/security-advisories/waiting-verification-backbox-os-denial-of-service/msg10218
https://www.exploit-db.com/exploits/41781/