PT-2017-2994 · Cisco · Cisco Ios Xe
Published
2017-09-27
·
Updated
2019-10-09
·
CVE-2017-12230
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software versions 16.2 and later, if the HTTP Server feature is enabled for the device.
Description
A vulnerability in the web-based user interface of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission settings for new users who are created by using the web UI of the affected software. An attacker could exploit this vulnerability by using the web UI to create a new user and then logging into the web UI as the newly created user. A successful exploit could allow the attacker to elevate their privileges on the affected device.
Recommendations
For Cisco IOS XE Software version 16.2, update to a version that includes the fix for this vulnerability.
For devices with the HTTP Server feature enabled, consider disabling the feature until a patch is applied.
As a temporary workaround, consider restricting access to the web-based user interface to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios Xe