CVE-2017-7397
BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7).
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). This product enables net.ipv4.conf.all.log_martians by default. NOTE: the vendor reports "It has been proved that this vulnerability has no foundation and it is totally fake and based on false assumptions.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 11.07% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- backbox/backbox linux
- Source
- cve@mitre.org
References
- http://www.exploitalert.com/view-details.html?id=26361Exploit, Third Party Advisory
- https://backbox.org/portal/blog/false-cve-backbox-46-unmaskedVendor Advisory
- https://cxsecurity.com/issue/WLB-2017040001Exploit, Third Party Advisory
- https://forum.backbox.org/security-advisories/waiting-verification-backbox-os-denial-of-service/msg10218Vendor Advisory
- https://www.exploit-db.com/exploits/41781/Exploit, Third Party Advisory, VDB Entry
- http://www.exploitalert.com/view-details.html?id=26361Exploit, Third Party Advisory
- https://backbox.org/portal/blog/false-cve-backbox-46-unmaskedVendor Advisory
- https://cxsecurity.com/issue/WLB-2017040001Exploit, Third Party Advisory
- https://forum.backbox.org/security-advisories/waiting-verification-backbox-os-denial-of-service/msg10218Vendor Advisory
- https://www.exploit-db.com/exploits/41781/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.