CVE-2017-12306
Last modified
CVE-2017-12306 is a vulnerability of currently unknown severity. A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade package, aka Signature Verification Bypass. The vulnerability is due to insufficient upgrade package validation. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade package, aka Signature Verification Bypass. The vulnerability is due to insufficient upgrade package validation. An attacker could exploit this vulnerability by providing the upgrade process with an upgrade package that the attacker controls. An exploit could allow the attacker to install custom firmware to the Spark Board. Cisco Bug IDs: CSCvf84502.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Conference Director | 2017-08-15 |
References
- http://www.securityfocus.com/bid/101914Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/101914Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12306?
How severe is CVE-2017-12306?
How do I fix CVE-2017-12306?
Are you affected by CVE-2017-12306?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
