THREATPORT/VULNERABILITY/CVE-2017-12226
HIGH SEVERITY

CVE-2017-12226

Ios Xe vulnerability

CVSS
8.8
EPSS
3.2%
EPSS pct
87th
Exploited
No known
A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco New Generation Wireless Controllers (NGWC) 3850 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incomplete input validation of HTTP requests by the affected GUI, if the GUI connection state or protocol changes. An attacker could exploit this vulnerability by authenticating to the Wireless Controller GUI as a Lobby Administrator user of an affected device and subsequently changing the state or protocol for their connection to the GUI. A successful exploit could allow the attacker to elevate their privilege level to administrator and gain full control of the affected device. This vulnerability affects the following Cisco products if they are running Cisco IOS XE Software Release 3.7.0E, 3.7.1E, 3.7.2E, 3.7.3E, 3.7.4E, or 3.7.5E: Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, Cisco New Generation Wireless Controllers (NGWC) 3850. Cisco Bug IDs: CSCvd73746.
Affected vendor
Cisco
Affected product
Ios Xe
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)
  • CWE-264 — Permissions, Privileges, and Access Controls
  • CWE-20 — Improper Input Validation
Published
2017-09-29

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring low privileges, no user interaction. Successful exploitation leads to high impact to confidentiality, high impact to integrity, high impact to availability.

Its EPSS score of 3.2% reflects a lower probability of exploitation activity in the wild over the next 30 days, placing it above 87% of all scored CVEs.

Check your external exposure to CVE-2017-12226

  • Confirm whether Cisco Ios Xe is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2017-12226.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2017-12226

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2017-12226 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2017-12226?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2017-12226.

Start free scan

No credit card. Agentless.