// For flags

CVE-2017-12226

 

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco New Generation Wireless Controllers (NGWC) 3850 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incomplete input validation of HTTP requests by the affected GUI, if the GUI connection state or protocol changes. An attacker could exploit this vulnerability by authenticating to the Wireless Controller GUI as a Lobby Administrator user of an affected device and subsequently changing the state or protocol for their connection to the GUI. A successful exploit could allow the attacker to elevate their privilege level to administrator and gain full control of the affected device. This vulnerability affects the following Cisco products if they are running Cisco IOS XE Software Release 3.7.0E, 3.7.1E, 3.7.2E, 3.7.3E, 3.7.4E, or 3.7.5E: Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, Cisco New Generation Wireless Controllers (NGWC) 3850. Cisco Bug IDs: CSCvd73746.

Una vulnerabilidad en la interfaz gráfica de usuario (GUI) web de los controladores de redes inalámbricas de Cisco IOS XE para los controladores Wireless LAN de Cisco 5760, los switches de Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) y Cisco New Generation Wireless Controllers (NGWC) 3850 podría permitir que un atacante remoto autenticado eleve sus privilegios en el dispositivo afectado. La vulnerabilidad se debe a una validación de entrada incompleta de las peticiones HTTP de la GUI afectada si el estado de conexión a la GUI o el protocolo cambia. Un atacante podría explotar esta vulnerabilidad autenticándose en la Wireless Controller GUI como un usuario Lobby Administrator de un dispositivo afectado y después cambiando el estado o protocolo para su conexión con la GUI. Un exploit exitoso podría permitir que el atacante eleve el nivel de privilegios a administrador y obtenga el control total del dispositivo afectado. La vulnerabilidad afecta a los siguientes productos de Cisco si ejecutan las distribuciones 3.7.0E, 3.7.1E, 3.7.2E, 3.7.3E, 3.7.4E o 3.7.5E del software de Cisco IOS XE: Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, Cisco New Generation Wireless Controllers (NGWC) 3850. Cisco Bug IDs: CSCvd73746.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-08-03 CVE Reserved
  • 2017-09-28 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.7.0e
Search vendor "Cisco" for product "Ios Xe" and version "3.7.0e"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.7.1e
Search vendor "Cisco" for product "Ios Xe" and version "3.7.1e"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.7.2e
Search vendor "Cisco" for product "Ios Xe" and version "3.7.2e"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.7.3e
Search vendor "Cisco" for product "Ios Xe" and version "3.7.3e"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.7.4e
Search vendor "Cisco" for product "Ios Xe" and version "3.7.4e"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.7.5e
Search vendor "Cisco" for product "Ios Xe" and version "3.7.5e"
-
Affected