PT-2017-2995 · Cisco · Cisco Ios Xe

Published

2017-09-27

·

Updated

2019-10-09

·

CVE-2017-12226

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software versions 3.7.0E through 3.7.5E
Description The issue is related to insufficient validation of HTTP requests in the web-based GUI of Cisco IOS XE Software for Wireless LAN Controllers. This could allow a remote attacker, authenticated as a Lobby Administrator, to elevate their privileges and gain full control of the device by changing the GUI connection state or protocol.
Recommendations For versions 3.7.0E through 3.7.5E, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Wireless Controller GUI to minimize the risk of exploitation. Avoid using the GUI connection as a Lobby Administrator until the issue is resolved.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02340
CVE-2017-12226

Affected Products

Cisco Ios Xe