CVE-2017-12214
Published on: 09/21/2017 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:26:30 PM UTC
Certain versions of Unified Customer Voice Portal from Cisco contain the following vulnerability:
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the OAMP and sending a crafted HTTP request. A successful exploit could allow the attacker to gain administrator privileges. The attacker must successfully authenticate to the system to exploit this vulnerability. This vulnerability affects Cisco Unified Customer Voice Portal (CVP) running software release 10.5, 11.0, or 11.5. Cisco Bug IDs: CSCve92752.
- CVE-2017-12214 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Unified Customer Voice Portal OAMP Password Reset Bug Lets Remote Authenticated Users Gain Elevated Privileges - SecurityTracker | Third Party Advisory VDB Entry www.securitytracker.com text/html |
![]() |
Cisco Unified Customer Voice Portal CVE-2017-12214 Remote Privilege Escalation Vulnerability | Third Party Advisory VDB Entry cve.report (archive) text/html |
![]() |
Cisco Unified Customer Voice Portal Operations Console Privilege Escalation Vulnerability | Vendor Advisory tools.cisco.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Unified Customer Voice Portal | 10.5 | All | All | All |
Application | Cisco | Unified Customer Voice Portal | 11.0 | All | All | All |
Application | Cisco | Unified Customer Voice Portal | 11.5 | All | All | All |
Application | Cisco | Unified Customer Voice Portal | 10.5 | All | All | All |
Application | Cisco | Unified Customer Voice Portal | 11.0 | All | All | All |
Application | Cisco | Unified Customer Voice Portal | 11.5 | All | All | All |
- cpe:2.3:a:cisco:unified_customer_voice_portal:10.5:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:unified_customer_voice_portal:11.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:unified_customer_voice_portal:11.5:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:unified_customer_voice_portal:10.5:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:unified_customer_voice_portal:11.0:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:unified_customer_voice_portal:11.5:*:*:*:*:*:*:*: