Lucene search

K
ciscoCiscoCISCO-SA-20171020-AMPFE
HistoryOct 20, 2017 - 9:00 p.m.

Cisco AMP for Endpoints Static Key Vulnerability

2017-10-2021:00:00
tools.cisco.com
53

EPSS

0

Percentile

5.1%

On October 20th, 2017, Cisco PSIRT was notified by the internal product team of a security vulnerability in the Cisco AMP For Endpoints application that would allow an authenticated, local attacker to access a static key value stored in the local application software.

The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker could exploit this vulnerability by gaining local, administrative access to a Windows host and stopping the Cisco AMP for Endpoints service.

Workarounds that address this vulnerability are available. This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171020-ampfe [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171020-ampfe”]

Affected configurations

Vulners
Node
ciscocisco_amp_for_endpointsMatchany
OR
ciscocisco_amp_for_endpointsMatchany
VendorProductVersionCPE
ciscocisco_amp_for_endpointsanycpe:2.3:a:cisco:cisco_amp_for_endpoints:any:*:*:*:*:*:*:*

EPSS

0

Percentile

5.1%

Related for CISCO-SA-20171020-AMPFE