CVE-2017-12331

CWE-3474 documents4 sources
Severity
6.7MEDIUM
EPSS
0.0%
top 89.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateMay 17

Description

A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verification for software patches. An authenticated, local attacker could exploit this vulnerability to bypass signature verification and load a crafted, unsigned software patch on a targeted device. The attacker would need valid administrator credentials to perform this exploit. This v

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages3 packages

NVDcisco/unified_computing_system7.0\(0\)hsk\(0.357\)
CVEListV5cisco_nx-osCisco NX-OS
NVDcisco/nx-os8.1\(1\)

🔴Vulnerability Details

2
GHSA
GHSA-8hxx-pmwx-5vvq: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software p2022-05-17
CVEList
CVE-2017-12331: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software p2017-11-30

📋Vendor Advisories

1
Cisco
Cisco NX-OS System Software Patch Signature Bypass Vulnerability2017-11-30
CVE-2017-12331 (MEDIUM CVSS 6.7) | A vulnerability in Cisco NX-OS Syst | cvebase.io