CVE-2017-7397
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 11%
from disclosure to weapon0 days
Published on NVDApr 3
1st PoCApr 2
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). This product enables net.ipv4.conf.all.log_martians by default. NOTE: the vendor reports "It has been proved that this vulnerability has no foundation and it is totally fake and based on false assumptions.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/41781/unverifiedexploitdbwww.exploit-db.com/exploits/41781unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://backbox.org/portal/blog/false-cve-backbox-46-unmaskedhttps://cxsecurity.com/issue/WLB-2017040001https://forum.backbox.org/security-advisories/waiting-verification-backbox-os-denial-of-service/msg10218https://www.exploit-db.com/exploits/41781/http://www.exploitalert.com/view-details.html?id=26361