CVE-2017-3867: Cisco Adaptive Security Appliance Software
Medium severity, CVSS 5.3. EPSS: 2.1% chance of exploitation in the next 30 days.
A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implementation of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to bypass the access control list (ACL) for specific TCP and UDP traffic. More Information: CSCvc68229. Known Affected Releases: 9.6(2). Known Fixed Releases: 99.1(20.1) 99.1(10.2) 98.1(12.7) 98.1(1.49) 97.1(6.58) 97.1(0.134) 96.2(0.109) 9.7(1.1) 9.6(2.99) 9.6(2.8).
Affected products
- Cisco Adaptive Security Appliance Software: version 6.3.1 only; version 9.6.2 only; version 9.6.2.1 only; version 9.6.2.2 only; version 9.6.2.3 only; version 9.6.2.7 only; …
Published 2017-03-17. Last modified 2026-06-17.