CVE-2017-12226
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco New Generation Wireless Controllers (NGWC) 3850 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incomplete input validation of HTTP requests by the affected GUI, if the GUI connection state or protocol changes. An attacker could exploit this vulnerability by authenticating to the Wireless Controller GUI as a Lobby Administrator user of an affected device and subsequently changing the state or protocol for their connection to the GUI. A successful exploit could allow the attacker to elevate their privilege level to administrator and gain full control of the affected device. This vulnerability affects the following Cisco products if they are running Cisco IOS XE Software Release 3.7.0E, 3.7.1E, 3.7.2E, 3.7.3E, 3.7.4E, or 3.7.5E: Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, Cisco New Generation Wireless Controllers (NGWC) 3850. Cisco Bug IDs: CSCvd73746.
Una vulnerabilidad en la interfaz gráfica de usuario (GUI) web de los controladores de redes inalámbricas de Cisco IOS XE para los controladores Wireless LAN de Cisco 5760, los switches de Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) y Cisco New Generation Wireless Controllers (NGWC) 3850 podría permitir que un atacante remoto autenticado eleve sus privilegios en el dispositivo afectado. La vulnerabilidad se debe a una validación de entrada incompleta de las peticiones HTTP de la GUI afectada si el estado de conexión a la GUI o el protocolo cambia. Un atacante podría explotar esta vulnerabilidad autenticándose en la Wireless Controller GUI como un usuario Lobby Administrator de un dispositivo afectado y después cambiando el estado o protocolo para su conexión con la GUI. Un exploit exitoso podría permitir que el atacante eleve el nivel de privilegios a administrador y obtenga el control total del dispositivo afectado. La vulnerabilidad afecta a los siguientes productos de Cisco si ejecutan las distribuciones 3.7.0E, 3.7.1E, 3.7.2E, 3.7.3E, 3.7.4E o 3.7.5E del software de Cisco IOS XE: Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, Cisco New Generation Wireless Controllers (NGWC) 3850. Cisco Bug IDs: CSCvd73746.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-03 CVE Reserved
- 2017-09-28 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101063 | Third Party Advisory | |
http://www.securitytracker.com/id/1039456 | Third Party Advisory | |
http://www.securitytracker.com/id/1039457 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-ngwc | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 3.7.0e Search vendor "Cisco" for product "Ios Xe" and version "3.7.0e" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 3.7.1e Search vendor "Cisco" for product "Ios Xe" and version "3.7.1e" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 3.7.2e Search vendor "Cisco" for product "Ios Xe" and version "3.7.2e" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 3.7.3e Search vendor "Cisco" for product "Ios Xe" and version "3.7.3e" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 3.7.4e Search vendor "Cisco" for product "Ios Xe" and version "3.7.4e" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 3.7.5e Search vendor "Cisco" for product "Ios Xe" and version "3.7.5e" | - |
Affected
|