CVE-2017-12214
published 2017-09-21CVE-2017-12214: A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal…
PriorityP355high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.18%
80.3th percentile
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the OAMP and sending a crafted HTTP request. A successful exploit could allow the attacker to gain administrator privileges. The attacker must successfully authenticate to the system to exploit this vulnerability. This vulnerability affects Cisco Unified Customer Voice Portal (CVP) running software release 10.5, 11.0, or 11.5. Cisco Bug IDs: CSCve92752.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal_operations | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Customer Voice Portal Operations Console Privilege Escalation Vulnerability
vendor_cisco·2017-09-20·CVSS 8.8
CVE-2017-12214 [HIGH] CWE-264 Cisco Unified Customer Voice Portal Operations Console Privilege Escalation Vulnerability
Cisco Unified Customer Voice Portal Operations Console Privilege Escalation Vulnerability
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges.
The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the OAMP and sending a crafted HTTP request. A successful exploit could allow the attacker to gain administrator privileges. The attacker must successfully authenticate to the system to exploit this vulnerability.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerabilit
Cisco
Cisco Unified Customer Voice Portal Operations Console Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12214 Cisco Unified Customer Voice Portal Operations Console Privilege Escalation Vulnerability
CVE-2017-12214: Cisco Unified Customer Voice Portal Operations Console Privilege Escalation Vulnerability
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the OAMP and sending a crafted HTTP request. A successful exploit could allow the attacker to gain administrator privileges. The attacker must successfully authenticate to the system to exploit this vulnerability. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-264, CWE-2
GHSA
GHSA-mgq9-pr3p-2gmg: A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voic
ghsa_unreviewed·2022-05-13
CVE-2017-12214 [HIGH] CWE-20 GHSA-mgq9-pr3p-2gmg: A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voic
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the OAMP and sending a crafted HTTP request. A successful exploit could allow the attacker to gain administrator privileges. The attacker must successfully authenticate to the system to exploit this vulnerability. This vulnerability affects Cisco Unified Customer Voice Portal (CVP) running software release 10.5, 11.0, or 11.5. Cisco Bug IDs: CSCve92752.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/100931http://www.securitytracker.com/id/1039411https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170920-cvphttp://www.securityfocus.com/bid/100931http://www.securitytracker.com/id/1039411https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170920-cvp
2017-09-21
Published