5.9

CVE-2017-12228

A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software. Cisco Bug IDs: CSCvc33171.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIos Xe Version <= 15.4\(3\)s
CiscoIos Xe Version3.3.0xo
CiscoIos Xe Version3.3.1xo
CiscoIos Xe Version3.3.2xo
CiscoIos Xe Version3.5.0e
CiscoIos Xe Version3.5.1e
CiscoIos Xe Version3.5.2e
CiscoIos Xe Version3.5.3e
CiscoIos Xe Version3.6.0e
CiscoIos Xe Version3.6.0s
CiscoIos Xe Version3.6.1e
CiscoIos Xe Version3.6.1s
CiscoIos Xe Version3.6.2ae
CiscoIos Xe Version3.6.2e
CiscoIos Xe Version3.6.2s
CiscoIos Xe Version3.6.3e
CiscoIos Xe Version3.6.4e
CiscoIos Xe Version3.6.5ae
CiscoIos Xe Version3.6.5be
CiscoIos Xe Version3.6.5e
CiscoIos Xe Version3.6.6e
CiscoIos Xe Version3.7.0bs
CiscoIos Xe Version3.7.0e
CiscoIos Xe Version3.7.0s
CiscoIos Xe Version3.7.1as
CiscoIos Xe Version3.7.1e
CiscoIos Xe Version3.7.1s
CiscoIos Xe Version3.7.2e
CiscoIos Xe Version3.7.2s
CiscoIos Xe Version3.7.2ts
CiscoIos Xe Version3.7.3e
CiscoIos Xe Version3.7.3s
CiscoIos Xe Version3.7.4as
CiscoIos Xe Version3.7.4e
CiscoIos Xe Version3.7.4s
CiscoIos Xe Version3.7.5e
CiscoIos Xe Version3.7.5s
CiscoIos Xe Version3.7.6s
CiscoIos Xe Version3.7.7s
CiscoIos Xe Version3.8.0e
CiscoIos Xe Version3.8.0ex
CiscoIos Xe Version3.8.0s
CiscoIos Xe Version3.8.1e
CiscoIos Xe Version3.8.1s
CiscoIos Xe Version3.8.2e
CiscoIos Xe Version3.8.2s
CiscoIos Xe Version3.8.3e
CiscoIos Xe Version3.8.4e
CiscoIos Xe Version3.9.0as
CiscoIos Xe Version3.9.0e
CiscoIos Xe Version3.9.0s
CiscoIos Xe Version3.9.1as
CiscoIos Xe Version3.9.1e
CiscoIos Xe Version3.9.1s
CiscoIos Xe Version3.9.2s
CiscoIos Xe Version3.10.0s
CiscoIos Xe Version3.10.1s
CiscoIos Xe Version3.10.1xbs
CiscoIos Xe Version3.10.2s
CiscoIos Xe Version3.10.2ts
CiscoIos Xe Version3.10.3s
CiscoIos Xe Version3.10.4s
CiscoIos Xe Version3.10.5s
CiscoIos Xe Version3.10.6s
CiscoIos Xe Version3.10.7s
CiscoIos Xe Version3.10.8as
CiscoIos Xe Version3.10.8s
CiscoIos Xe Version3.10.9s
CiscoIos Xe Version3.11.0s
CiscoIos Xe Version3.11.1s
CiscoIos Xe Version3.11.2s
CiscoIos Xe Version3.11.3s
CiscoIos Xe Version3.11.4s
CiscoIos Xe Version3.12.0as
CiscoIos Xe Version3.12.0s
CiscoIos Xe Version3.12.1s
CiscoIos Xe Version3.12.2s
CiscoIos Xe Version3.12.3s
CiscoIos Xe Version3.12.4s
CiscoIos Xe Version3.13.0as
CiscoIos Xe Version3.13.0s
CiscoIos Xe Version3.13.1s
CiscoIos Xe Version3.13.2as
CiscoIos Xe Version3.13.2s
CiscoIos Xe Version3.13.3s
CiscoIos Xe Version3.13.4s
CiscoIos Xe Version3.13.5as
CiscoIos Xe Version3.13.5s
CiscoIos Xe Version3.13.6as
CiscoIos Xe Version3.13.6s
CiscoIos Xe Version3.13.7as
CiscoIos Xe Version3.13.7s
CiscoIos Xe Version3.14.0s
CiscoIos Xe Version3.14.1s
CiscoIos Xe Version3.14.2s
CiscoIos Xe Version3.14.3s
CiscoIos Xe Version3.14.4s
CiscoIos Xe Version3.15.0s
CiscoIos Xe Version3.15.1cs
CiscoIos Xe Version3.15.1s
CiscoIos Xe Version3.15.2s
CiscoIos Xe Version3.15.3s
CiscoIos Xe Version3.15.4s
CiscoIos Xe Version3.16.0cs
CiscoIos Xe Version3.16.0s
CiscoIos Xe Version3.16.1as
CiscoIos Xe Version3.16.1s
CiscoIos Xe Version3.16.2as
CiscoIos Xe Version3.16.2bs
CiscoIos Xe Version3.16.2s
CiscoIos Xe Version3.16.3as
CiscoIos Xe Version3.16.3s
CiscoIos Xe Version3.16.4as
CiscoIos Xe Version3.16.4bs
CiscoIos Xe Version3.16.4ds
CiscoIos Xe Version3.16.4s
CiscoIos Xe Version3.16.5s
CiscoIos Xe Version3.17.0s
CiscoIos Xe Version3.17.1as
CiscoIos Xe Version3.17.1s
CiscoIos Xe Version3.17.3s
CiscoIos Xe Version3.18.0as
CiscoIos Xe Version3.18.0s
CiscoIos Xe Version3.18.0sp
CiscoIos Xe Version3.18.1asp
CiscoIos Xe Version3.18.1bsp
CiscoIos Xe Version3.18.1csp
CiscoIos Xe Version3.18.1s
CiscoIos Xe Version3.18.1sp
CiscoIos Xe Version3.18.2s
CiscoIos Xe Version3.18.2sp
CiscoIos Xe Version3.18.3vs
CiscoIos Xe Version16.1.1
CiscoIos Xe Version16.1.2
CiscoIos Xe Version16.1.3
CiscoIos Xe Version16.1.3a
CiscoIos Xe Version16.1.4
CiscoIos Xe Version16.2.1
CiscoIos Xe Version16.2.2
CiscoIos Xe Version16.2.2a
CiscoIos Xe Version16.2.3
CiscoIos Xe Version16.3.1
CiscoIos Xe Version16.3.1a
CiscoIos Xe Version16.3.2
CiscoIos Xe Version16.4.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.549
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.