Lucene search

K
cveCiscoCVE-2017-12223
HistorySep 07, 2017 - 9:29 p.m.

CVE-2017-12223

2017-09-0721:29:00
CWE-20
cisco
web.nvd.nist.gov
48
cisco
ir800
integrated services router
rom monitor
rommon
vulnerability
nvd
cisco bug ids
cscvb44027

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

6.4

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

35.4%

A vulnerability in the ROM Monitor (ROMMON) code of Cisco IR800 Integrated Services Router Software could allow an unauthenticated, local attacker to boot an unsigned Hypervisor on an affected device and compromise the integrity of the system. The vulnerability is due to insufficient sanitization of user input. An attacker who can access an affected router via the console could exploit this vulnerability by entering ROMMON mode and modifying ROMMON variables. A successful exploit could allow the attacker to execute arbitrary code and install a malicious version of Hypervisor firmware on an affected device. Cisco Bug IDs: CSCvb44027.

Affected configurations

Nvd
Node
ciscoir800_integrated_services_router_firmwareMatch-
AND
ciscoir800_integrated_services_routerMatch-
VendorProductVersionCPE
ciscoir800_integrated_services_router_firmware-cpe:2.3:o:cisco:ir800_integrated_services_router_firmware:-:*:*:*:*:*:*:*
ciscoir800_integrated_services_router-cpe:2.3:h:cisco:ir800_integrated_services_router:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco IR800 Integrated Services Router",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco IR800 Integrated Services Router"
      }
    ]
  }
]

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

6.4

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

35.4%

Related for CVE-2017-12223