cbcvebase.
CVE-2017-12352
published 2017-11-30

CVE-2017-12352: A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an…

PriorityP434medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.45%
36.4th percentile
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute arbitrary commands with root privileges on an affected host operating system. The vulnerability is due to insufficient validation of user-controlled input that is supplied to certain script files of an affected system. An attacker could exploit this vulnerability by submitting crafted input to a script file on an affected system. A successful exploit could allow the attacker to gain elevated privileges and execute arbitrary commands with root privileges on the affected system. To exploit this vulnerability, the attacker would need to authenticate to the affected system by using valid administrator credentials. Cisco Bug IDs: CSCvf57274.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscoapplication_policy_infrastructure_controller
ciscoapplication_policy_infrastructure_controller_local

CVSS provenance

nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.