CVE-2017-12373
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652.
Una vulnerabilidad en la implementación del protocolo TLS de dispositivos heredados Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540 y 5550)podría permitir que un atacante remoto no autenticado acceda a información sensible. Esto también se conoce como ataque ROBOT (Return of Bleichenbacher's Oracle Threat). Un atacante podría consultar repetidamente un servidor que ejecuta una implementación de la pila TLS vulnerable para realizar operaciones criptoanalíticas que podrían permitir la descodificación de sesiones TLS previamente capturadas. Cisco Bug IDs: CSCvg97652.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-03 CVE Reserved
- 2017-12-15 CVE Published
- 2023-05-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-203: Observable Discrepancy
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102170 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Adaptive Security Appliance 5505 Firmware Search vendor "Cisco" for product "Adaptive Security Appliance 5505 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Adaptive Security Appliance 5505 Search vendor "Cisco" for product "Adaptive Security Appliance 5505" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance 5510 Firmware Search vendor "Cisco" for product "Adaptive Security Appliance 5510 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Adaptive Security Appliance 5510 Search vendor "Cisco" for product "Adaptive Security Appliance 5510" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance 5520 Firmware Search vendor "Cisco" for product "Adaptive Security Appliance 5520 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Adaptive Security Appliance 5520 Search vendor "Cisco" for product "Adaptive Security Appliance 5520" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance 5540 Firmware Search vendor "Cisco" for product "Adaptive Security Appliance 5540 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Adaptive Security Appliance 5540 Search vendor "Cisco" for product "Adaptive Security Appliance 5540" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance 5550 Firmware Search vendor "Cisco" for product "Adaptive Security Appliance 5550 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Adaptive Security Appliance 5550 Search vendor "Cisco" for product "Adaptive Security Appliance 5550" | - | - |
Safe
|