#VU8690 Privilege escalation in Cisco IOS XE - CVE-2017-12226

 

#VU8690 Privilege escalation in Cisco IOS XE - CVE-2017-12226

Published: October 4, 2017


Vulnerability identifier: #VU8690
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2017-12226
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco IOS XE
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.

The weakness exists in the web-based Wireless Controller GUI of Cisco IOS XE Software due to incomplete input validation of HTTP requests by the affected GUI, if the GUI connection state or protocol changes. A remote attacker can authenticate to the Wireless Controller GUI as a Lobby Administrator user, change the state or protocol for connection to the GUI, obtain administrator privileges and gain full control over the affected device.

Remediation

Install update from vendor's website.

External links