Privilege escalation in Cisco IOS XE - CVE-2017-12226

 

Privilege escalation in Cisco IOS XE - CVE-2017-12226

Published: October 4, 2017


Vulnerability identifier: #VU8690
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12226
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.

The weakness exists in the web-based Wireless Controller GUI of Cisco IOS XE Software due to incomplete input validation of HTTP requests by the affected GUI, if the GUI connection state or protocol changes. A remote attacker can authenticate to the Wireless Controller GUI as a Lobby Administrator user, change the state or protocol for connection to the GUI, obtain administrator privileges and gain full control over the affected device.

Affected software

Cisco IOS XE

How to mitigate CVE-2017-12226

Install update from vendor's website.


External References

Related Security Bulletins