Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2017-3224

8.2 · HIGH
Published Jul 24, 2018 quagga CWE-354 EPSS 1.06% (62th pctl)

Overview

CVE-2017-3224 is a high-severity vulnerability affecting quagga quagga. It was published on July 24, 2018 and has a CVSS 3.0 base score of 8.2 (HIGH).

This vulnerability has a CVSS 3.0 base score of 8.2, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

Technical Description

Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence numbers, then checksums, and finally MaxAge. In a case where the sequence numbers are the same, the LSA with the larger checksum is considered more recent, and will not be flushed from the Link State Database (LSDB). Since the RFC does not explicitly state that the values of links carried by a LSA must be the same when prematurely aging a self-originating LSA with MaxSequenceNumber, it is possible in vulnerable OSPF implementations for an attacker to craft a LSA with MaxSequenceNumber and invalid links that will result in a larger checksum and thus a 'newer' LSA that will not be flushed from the LSDB. Propagation of the crafted LSA can result in the erasure or alteration of the routing tables of routers within the r

Remediation

Check the references section for vendor advisories and patches from quagga. Update quagga to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status

Frequently Asked Questions

What is CVE-2017-3224?

CVE-2017-3224 is a high-severity vulnerability affecting quagga quagga. It was published on July 24, 2018 and has a CVSS 3.0 base score of 8.2 (HIGH).

How severe is CVE-2017-3224?

This vulnerability has a CVSS 3.0 base score of 8.2, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2017-3224?

Check the references section for vendor advisories and patches from quagga. Update quagga to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2017-3224?

CyberStrike's AI-powered security agents can automatically detect CVE-2017-3224 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.