CVE-2017-12223
Summary
| CVE | CVE-2017-12223 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-07 21:29:00 UTC |
| Updated | 2019-10-09 23:22:00 UTC |
| Description | A vulnerability in the ROM Monitor (ROMMON) code of Cisco IR800 Integrated Services Router Software could allow an unauthenticated, local attacker to boot an unsigned Hypervisor on an affected device and compromise the integrity of the system. The vulnerability is due to insufficient sanitization of user input. An attacker who can access an affected router via the console could exploit this vulnerability by entering ROMMON mode and modifying ROMMON variables. A successful exploit could allow the attacker to execute arbitrary code and install a malicious version of Hypervisor firmware on an affected device. Cisco Bug IDs: CSCvb44027. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Ir800 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | Ir800 Integrated Services Router | - | All | All | All |
| Operating System | Cisco | Ir800 Integrated Services Router Firmware | - | All | All | All |
| Operating System | Cisco | Ir800 Integrated Services Router Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IR800 Integrated Services Routers Input Validation Flaw Lets Local Users Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco IR800 Integrated Services Router ROM Monitor Input Validation Vulnerability | CONFIRM | tools.cisco.com | Vendor Advisory |
| Cisco IR800 Integrated Services Router Software CVE-2017-12223 Local Code Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.