CVE-2017-12096
Last modified
CVE-2017-12096 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An exploitable vulnerability exists in the WiFi management of Circle with Disney. A crafted Access Point with the same name as the legitimate one can be used to make Circle connect to an untrusted network. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
An exploitable vulnerability exists in the WiFi management of Circle with Disney. A crafted Access Point with the same name as the legitimate one can be used to make Circle connect to an untrusted network. An attacker needs to setup an Access Point reachable by the device and to send a series of spoofed "deauth" packets to trigger this vulnerability.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Meetcircle | Circle With Disney Firmware | 2.0.1 |
References
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0448Exploit, Technical Description, Third Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0448Exploit, Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12096?
How severe is CVE-2017-12096?
How do I fix CVE-2017-12096?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-12090An exploitable denial of service vulnerability exists in the…7.7
- CVE-2017-12091Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-12092An exploitable file write vulnerability exists in the memory…3.7
- CVE-2017-12093An exploitable insufficient resource pool vulnerability exis…5.3
- CVE-2017-12094An exploitable vulnerability exists in the WiFi Channel pars…7.4
- CVE-2017-12095An exploitable vulnerability exists in the WiFi Access Point…6.5
- CVE-2017-12097An exploitable cross site scripting (XSS) vulnerability exis…6.1
- CVE-2017-12098An exploitable cross site scripting (XSS) vulnerability exis…6.1
- CVE-2017-12099An exploitable integer overflow exists in the upgrade of the…7.8
- CVE-2017-1210IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 a…
- CVE-2017-12100An exploitable integer overflow exists in the 'multires_load…7.8
- CVE-2017-12101An exploitable integer overflow exists in the 'modifier_mdef…7.8
Are you affected by CVE-2017-12096?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
