PT-2017-2995 · Cisco · Cisco Ios Xe
Published
2017-09-27
·
Updated
2019-10-09
·
CVE-2017-12226
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software versions 3.7.0E through 3.7.5E
Description
The issue is related to insufficient validation of HTTP requests in the web-based GUI of Cisco IOS XE Software for Wireless LAN Controllers. This could allow a remote attacker, authenticated as a Lobby Administrator, to elevate their privileges and gain full control of the device by changing the GUI connection state or protocol.
Recommendations
For versions 3.7.0E through 3.7.5E, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Wireless Controller GUI to minimize the risk of exploitation. Avoid using the GUI connection as a Lobby Administrator until the issue is resolved.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios Xe