CVE-2017-12236
Last modified
CVE-2017-12236 is a vulnerability of currently unknown severity. A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, remote attacker using an x tunnel router to bypass authentication checks performed when registering an Endpoint Identifier (EID) to a Routing Locator (RLOC) in the map server/map resolver (MS/MR). The vulnerability is due to a logic error introduced via a code regression for the affected software. EPSS estimates a 3.12% chance of exploitation in the next 30 days.
Description
A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, remote attacker using an x tunnel router to bypass authentication checks performed when registering an Endpoint Identifier (EID) to a Routing Locator (RLOC) in the map server/map resolver (MS/MR). The vulnerability is due to a logic error introduced via a code regression for the affected software. An attacker could exploit this vulnerability by sending specific valid map-registration requests, which will be accepted by the MS/MR even if the authentication keys do not match, to the affected software. A successful exploit could allow the attacker to inject invalid mappings of EIDs to RLOCs in the MS/MR of the affected software. This vulnerability affects Cisco devices that are configured with LISP acting as an IPv4 or IPv6 map server. This vulnerability affects Cisco IOS XE Software release trains 3.9E and Everest 16.4. Cisco Bug IDs: CSCvc18008.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.2.0ja |
| Cisco | Ios Xe | 3.9.1e |
| Cisco | Ios Xe | 16.5.1c |
References
- http://www.securityfocus.com/bid/101033Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039448Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101033Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039448Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12236?
How severe is CVE-2017-12236?
How do I fix CVE-2017-12236?
Are you affected by CVE-2017-12236?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
