10

CVE-2017-12229

A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affected software. The vulnerability is due to insufficient input validation for the REST API of the affected software. An attacker could exploit this vulnerability by sending a malicious API request to an affected device. A successful exploit could allow the attacker to bypass authentication and gain access to the web UI of the affected software. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the HTTP Server feature is enabled for the device. The newly redesigned, web-based administration UI was introduced in the Denali 16.2 Release of Cisco IOS XE Software. This vulnerability does not affect the web-based administration UI in earlier releases of Cisco IOS XE Software. Cisco Bug IDs: CSCuz46036.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Xe Version 3.1.3as
Cisco ≫ Ios Xe Version 3.2.0ja
Cisco ≫ Ios Xe Version 3.2.1xo
Cisco ≫ Ios Xe Version 3.4.7asg
Cisco ≫ Ios Xe Version 3.6.5be
Cisco ≫ Ios Xe Version 3.8.0ex
Cisco ≫ Ios Xe Version 3.18.3vs
Cisco ≫ Ios Xe Version 16.1.1
Cisco ≫ Ios Xe Version 16.1.2
Cisco ≫ Ios Xe Version 16.1.3
Cisco ≫ Ios Xe Version 16.1.3a
Cisco ≫ Ios Xe Version 16.1.4
Cisco ≫ Ios Xe Version 16.2.1
Cisco ≫ Ios Xe Version 16.2.2a
Cisco ≫ Ios Xe Version 16.3.1a
Cisco ≫ Ios Xe Version 16.5.1a
Cisco ≫ Ios Xe Version 16.5.1c
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.17% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://www.securityfocus.com/bid/101032
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1039447
Third Party Advisory
VDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-restapi
Vendor Advisory