PT-2017-12418 · Cisco · Cisco Ios Xe+2

Publicado

2017-09-27

·

Atualizado

2019-10-09

·

CVE-2017-12228

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.4 through 15.6 Cisco IOS XE versions 3.3 through 16.4
Description A vulnerability in the Cisco Network Plug and Play application could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.
Recommendations For Cisco IOS versions 12.4 through 15.6, update to a fixed software version. For Cisco IOS XE versions 3.3 through 16.4, update to a fixed software version. As a general mitigation measure, ensure that all software updates are applied as soon as they become available, and consider implementing additional security measures to detect and prevent man-in-the-middle attacks.

Correção

RCE

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-12228

Produtos afetados

Cisco Ios
Cisco Ios Xe
Cisco Network Plug/Play