Privilege escalation in Cisco Emergency Responder - CVE-2017-12337

 

Privilege escalation in Cisco Emergency Responder - CVE-2017-12337

Published: November 21, 2017


Vulnerability identifier: #VU9387
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12337
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain elevated privileges on the target system.

The weakness exists in Cisco Voice Operating System (VOS) software platform device due to improper authentication when a refresh upgrade or Prime Collaboration Deployment (PCD) migration is performed. A remote attacker can gain root access to the device with a known password and compromise the affected system.

Affected software

Cisco Emergency Responder
Cisco MediaSense
Cisco Hosted Collaboration
Cisco Finesse
Unified Communications Manager (CallManager)
Cisco Unity Connection
Customer Collaboration Platform (CCP)
Cisco Unified Intelligence Center

How to mitigate CVE-2017-12337

The vulnerability is addressed in the following versions: CER.12.0(1.11900.5), CER.11.5(4.20000.2).


External References

Related Security Bulletins