CVE-2017-12373
Summary
| CVE | CVE-2017-12373 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-15 20:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652. |
Risk And Classification
Primary CVSS: v3.0 5.9 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.669440000 probability, percentile 0.985690000 (date 2026-05-18)
Problem Types: CWE-200 | CWE-203 | CWE-200 CWE-200
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.9 | MEDIUM | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 4.3 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Adaptive Security Appliance 5505 | - | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance 5505 Firmware | - | All | All | All |
| Hardware | Cisco | Adaptive Security Appliance 5510 | - | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance 5510 Firmware | - | All | All | All |
| Hardware | Cisco | Adaptive Security Appliance 5520 | - | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance 5520 Firmware | - | All | All | All |
| Hardware | Cisco | Adaptive Security Appliance 5540 | - | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance 5540 Firmware | - | All | All | All |
| Hardware | Cisco | Adaptive Security Appliance 5550 | - | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance 5550 Firmware | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Cisco Legacy ASA 5500 Products TLS Protocol Implementation | affected Cisco legacy ASA 5500 products TLS protocol implementation | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Cisco Products Multiple Information Disclosure Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Bleichenbacher Attack on TLS Affecting Cisco Products: December 2017 | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Issue Tracking, Mitigation, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.