CVE-2017-12228 Details
Description
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software. Cisco Bug IDs: CSCvc33171.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-pnp | CVE | Vendor Advisory |
| http://www.securityfocus.com/bid/101065 | CVE | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039450 | CVE | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-pnp | [email protected] | Vendor Advisory |
| http://www.securityfocus.com/bid/101065 | [email protected] | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039450 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios | 12.4(25e)jao3a 12.4(25e)jao20s 12.4(25e)jap1n 12.4(25e)jap9 15.0(2)ej 15.0(2)ej1 15.0(2)ex 15.0(2)ex1 15.0(2)ex2 15.0(2)ex3 15.0(2)ex4 15.0(2)ex5 15.0(2)ex8 15.0(2)ex10 15.0(2)ex13 15.0(2)ez 15.0(2)se1 15.0(2)se2 15.0(2)se3 15.0(2)se4 15.0(2)se5 15.0(2)se6 15.0(2)se7 15.0(2)se8 15.0(2)se9 15.0(2)se10 15.0(2)se10a 15.0(2)sqd7 15.0(2a)ex5 15.0(2a)se9 15.1(1)sy 15.1(1)sy1 15.1(1)sy2 15.1(1)sy3 15.1(1)sy4 15.1(1)sy5 15.1(1)sy6 15.1(2)sg7a 15.1(2)sy 15.1(2)sy1 15.1(2)sy2 15.1(2)sy3 15.1(2)sy4 15.1(2)sy4a 15.1(2)sy5 15.1(2)sy6 15.1(2)sy7 15.1(2)sy8 15.1(2)sy9 15.1(2)sy10 15.2(1)e 15.2(1)e1 15.2(1)e2 15.2(1)e3 15.2(1)ey 15.2(1)sy 15.2(1)sy0a 15.2(1)sy1 15.2(1)sy1a 15.2(1)sy2 15.2(1)sy3 15.2(1)sy4 15.2(2)e 15.2(2)e1 15.2(2)e2 15.2(2)e3 15.2(2)e4 15.2(2)e5 15.2(2)e5a 15.2(2)e5b 15.2(2)e6 15.2(2)ea1 15.2(2)ea2 15.2(2)ea3 15.2(2)eb 15.2(2)eb1 15.2(2)eb2 15.2(2)gc 15.2(2)ja 15.2(2)ja1 15.2(2)jax 15.2(2)jax1 15.2(2)jb 15.2(2)jb2 15.2(2)jb3 15.2(2)jb4 15.2(2)jb5 15.2(2)jb6 15.2(2)jn1 15.2(2)jn2 15.2(2)s 15.2(2)s0a 15.2(2)s0c 15.2(2)s1 15.2(2)s2 15.2(2)sng 15.2(2)snh1 15.2(2)sni 15.2(2)sy 15.2(2)sy1 15.2(2)sy2 15.2(2)t 15.2(2)t1 15.2(2)t2 15.2(2)t3 15.2(2)t4 15.2(2a)e1 15.2(2a)e2 15.2(3)e 15.2(3)e1 15.2(3)e2 15.2(3)e3 15.2(3)e4 15.2(3)e5 15.2(3)ea 15.2(3)ex 15.2(3)gc 15.2(3)gc1 15.2(3)t 15.2(3)t1 15.2(3)t2 15.2(3)t3 15.2(3)t4 15.2(3a)e 15.2(3m)e2 15.2(3m)e3 15.2(3m)e8 15.2(4)e 15.2(4)e1 15.2(4)e2 15.2(4)e3 15.2(4)e4 15.2(4)ea 15.2(4)ea1 15.2(4)ea3 15.2(4)ea4 15.2(4)ea5 15.2(4)ec 15.2(4)ec1 15.2(4)ec2 15.2(4)gc 15.2(4)gc1 15.2(4)gc2 15.2(4)gc3 15.2(4)ja 15.2(4)ja1 15.2(4)jb 15.2(4)jb1 15.2(4)jb2 15.2(4)jb3 15.2(4)jb3a 15.2(4)jb3b 15.2(4)jb3h 15.2(4)jb3s 15.2(4)jb4 15.2(4)jb5 15.2(4)jb5h 15.2(4)jb5m 15.2(4)jb6 15.2(4)jb7 15.2(4)jn 15.2(4)m 15.2(4)m1 15.2(4)m2 15.2(4)m3 15.2(4)m4 15.2(4)m5 15.2(4)m6 15.2(4)m6a 15.2(4)m7 15.2(4)m8 15.2(4)m9 15.2(4)m10 15.2(4)m11 15.2(4)s 15.2(4)s1 15.2(4)s2 15.2(4)s3 15.2(4)s3a 15.2(4)s4 15.2(4)s4a 15.2(4)s5 15.2(4)s6 15.2(4)s7 15.2(4m)e1 15.2(4m)e3 15.2(4n)e2 15.2(4o)e2 15.2(4p)e1 15.2(5)e 15.2(5)e1 15.2(5)e2a 15.2(5)e2b 15.2(5)ea 15.2(5)ex 15.2(5a)e 15.2(5a)e1 15.2(5b)e 15.2(5c)e 15.3(1)s 15.3(1)s1 15.3(1)s2 15.3(1)sy 15.3(1)sy1 15.3(1)sy2 15.3(1)t 15.3(1)t1 15.3(1)t2 15.3(1)t3 15.3(1)t4 15.3(2)s 15.3(2)s1 15.3(2)s2 15.3(2)t 15.3(2)t1 15.3(2)t2 15.3(2)t3 15.3(2)t4 15.3(3)ja 15.3(3)ja1 15.3(3)ja1m 15.3(3)ja1n 15.3(3)ja4 15.3(3)ja5 15.3(3)ja6 15.3(3)ja7 15.3(3)ja8 15.3(3)ja10 15.3(3)ja11 15.3(3)ja76 15.3(3)ja77 15.3(3)jaa 15.3(3)jab 15.3(3)jax 15.3(3)jax1 15.3(3)jax2 15.3(3)jb 15.3(3)jb75 15.3(3)jbb 15.3(3)jbb1 15.3(3)jbb2 15.3(3)jbb4 15.3(3)jbb5 15.3(3)jbb6 15.3(3)jbb6a 15.3(3)jbb8 15.3(3)jbb50 15.3(3)jc 15.3(3)jc1 15.3(3)jc2 15.3(3)jc3 15.3(3)jc4 15.3(3)jc5 15.3(3)jc6 15.3(3)jc7 15.3(3)jc50 15.3(3)jc51 15.3(3)jca7 15.3(3)jd 15.3(3)jd2 15.3(3)jd3 15.3(3)jd4 15.3(3)jda3 15.3(3)je 15.3(3)je1 15.3(3)jn3 15.3(3)jn4 15.3(3)jn7 15.3(3)jn8 15.3(3)jn9 15.3(3)jnb 15.3(3)jnb1 15.3(3)jnb2 15.3(3)jnb3 15.3(3)jnb4 15.3(3)jnb6 15.3(3)jnc 15.3(3)jnc1 15.3(3)jnc4 15.3(3)jnd 15.3(3)jnd1 15.3(3)jnd2 15.3(3)jnd3 15.3(3)jnp 15.3(3)jnp1 15.3(3)jnp2 15.3(3)jpb 15.3(3)jpb1 15.3(3)jpb2 15.3(3)jpc2 15.3(3)jpc3 15.3(3)jpd 15.3(3)m 15.3(3)m1 15.3(3)m2 15.3(3)m3 15.3(3)m4 15.3(3)m5 15.3(3)m6 15.3(3)m7 15.3(3)m8 15.3(3)m8a 15.3(3)m9 15.3(3)s 15.3(3)s1 15.3(3)s1a 15.3(3)s2 15.3(3)s3 15.3(3)s4 15.3(3)s5 15.3(3)s6 15.3(3)s7 15.3(3)s8 15.3(3)s8a 15.3(3)s9 15.4(1)cg 15.4(1)cg1 15.4(1)s 15.4(1)s1 15.4(1)s2 15.4(1)s3 15.4(1)s4 15.4(1)sy 15.4(1)sy1 15.4(1)sy2 15.4(1)t 15.4(1)t1 15.4(1)t2 15.4(1)t3 15.4(1)t4 15.4(2)cg 15.4(2)s 15.4(2)s1 15.4(2)s2 15.4(2)s3 15.4(2)s4 15.4(2)t 15.4(2)t1 15.4(2)t2 15.4(2)t3 15.4(2)t4 15.4(3)m 15.4(3)m1 15.4(3)m2 15.4(3)m3 15.4(3)m4 15.4(3)m5 15.4(3)m6 15.4(3)m6a 15.4(3)m7 15.4(3)s 15.4(3)s1 15.4(3)s2 15.4(3)s3 15.4(3)s4 15.4(3)s5 15.4(3)s5a 15.4(3)s6 15.4(3)s6a 15.4(3)s6b 15.4(3)s7 15.4(3)s7a 15.5(1)s 15.5(1)s1 15.5(1)s2 15.5(1)s3 15.5(1)s4 15.5(1)sy 15.5(1)sy1 15.5(1)t 15.5(1)t1 15.5(1)t2 15.5(1)t3 15.5(1)t4 15.5(2)s 15.5(2)s1 15.5(2)s2 15.5(2)s3 15.5(2)s4 15.5(2)t 15.5(2)t1 15.5(2)t2 15.5(2)t3 15.5(2)t4 15.5(3)m 15.5(3)m0a 15.5(3)m1 15.5(3)m2 15.5(3)m3 15.5(3)m4 15.5(3)m4a 15.5(3)m5 15.5(3)s 15.5(3)s0a 15.5(3)s1 15.5(3)s1a 15.5(3)s2 15.5(3)s2a 15.5(3)s2b 15.5(3)s3 15.5(3)s3a 15.5(3)s4 15.5(3)s4a 15.5(3)s4b 15.5(3)s4d 15.5(3)s5 15.5(3)sn 15.6(1)s 15.6(1)s1 15.6(1)s1a 15.6(1)s2 15.6(1)s3 15.6(1)t 15.6(1)t0a 15.6(1)t1 15.6(1)t2 15.6(1)t3 15.6(2)s 15.6(2)s0a 15.6(2)s1 15.6(2)s2 15.6(2)s3 15.6(2)sn 15.6(2)sp 15.6(2)sp1 15.6(2)sp1b 15.6(2)sp1c 15.6(2)sp2 15.6(2)sp2a 15.6(2)t 15.6(2)t1 15.6(2)t2 15.6(3)m 15.6(3)m0a 15.6(3)m1 15.6(3)m1b |
CPE
Remediation
| |
| cisco ios xe | <= 15.4\(3\)s 3.3.0xo 3.3.1xo 3.3.2xo 3.5.0e 3.5.1e 3.5.2e 3.5.3e 3.6.0e 3.6.0s 3.6.1e 3.6.1s 3.6.2ae 3.6.2e 3.6.2s 3.6.3e 3.6.4e 3.6.5ae 3.6.5be 3.6.5e 3.6.6e 3.7.0bs 3.7.0e 3.7.0s 3.7.1as 3.7.1e 3.7.1s 3.7.2e 3.7.2s 3.7.2ts 3.7.3e 3.7.3s 3.7.4as 3.7.4e 3.7.4s 3.7.5e 3.7.5s 3.7.6s 3.7.7s 3.8.0e 3.8.0ex 3.8.0s 3.8.1e 3.8.1s 3.8.2e 3.8.2s 3.8.3e 3.8.4e 3.9.0as 3.9.0e 3.9.0s 3.9.1as 3.9.1e 3.9.1s 3.9.2s 3.10.0s 3.10.1s 3.10.1xbs 3.10.2s 3.10.2ts 3.10.3s 3.10.4s 3.10.5s 3.10.6s 3.10.7s 3.10.8as 3.10.8s 3.10.9s 3.11.0s 3.11.1s 3.11.2s 3.11.3s 3.11.4s 3.12.0as 3.12.0s 3.12.1s 3.12.2s 3.12.3s 3.12.4s 3.13.0as 3.13.0s 3.13.1s 3.13.2as 3.13.2s 3.13.3s 3.13.4s 3.13.5as 3.13.5s 3.13.6as 3.13.6s 3.13.7as 3.13.7s 3.14.0s 3.14.1s 3.14.2s 3.14.3s 3.14.4s 3.15.0s 3.15.1cs 3.15.1s 3.15.2s 3.15.3s 3.15.4s 3.16.0cs 3.16.0s 3.16.1as 3.16.1s 3.16.2as 3.16.2bs 3.16.2s 3.16.3as 3.16.3s 3.16.4as 3.16.4bs 3.16.4ds 3.16.4s 3.16.5s 3.17.0s 3.17.1as 3.17.1s 3.17.3s 3.18.0as 3.18.0s 3.18.0sp 3.18.1asp 3.18.1bsp 3.18.1csp 3.18.1s 3.18.1sp 3.18.2s 3.18.2sp 3.18.3vs 16.1.1 16.1.2 16.1.3 16.1.3a 16.1.4 16.2.1 16.2.2 16.2.2a 16.2.3 16.3.1 16.3.1a 16.3.2 16.4.1 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Oct 6, 2017 | Initial Analysis | [email protected] |
| Oct 3, 2017 | CVE Modified | [email protected] |