Vulnerability Description
Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Traps | <= 3.4.3 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/97533Third Party AdvisoryVDB Entry
- https://security.paloaltonetworks.com/CVE-2017-7408Vendor Advisory
- https://www.paloaltonetworks.com/documentation/34/endpoint/traps-release-notes/tRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/97533Third Party AdvisoryVDB Entry
- https://security.paloaltonetworks.com/CVE-2017-7408Vendor Advisory
- https://www.paloaltonetworks.com/documentation/34/endpoint/traps-release-notes/tRelease NotesVendor Advisory
FAQ
What is CVE-2017-7408?
CVE-2017-7408 is a vulnerability with a CVSS score of 7.5 (HIGH). Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.
How severe is CVE-2017-7408?
CVE-2017-7408 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7408?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Traps.