6.8
CVSSv3

CVE-2017-12239

Published: 29/09/2017 Updated: 05/02/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical malicious user to access an affected device's operating system. The vulnerability exists because an engineering console port is available on the motherboard of the affected line cards. An attacker could exploit this vulnerability by physically connecting to the console port on the line card. A successful exploit could allow the malicious user to gain full access to the affected device's operating system. This vulnerability affects only Cisco ASR 1000 Series Routers that have removable line cards and Cisco cBR-8 Converged Broadband Routers, if they are running certain Cisco IOS XE 3.16 up to and including 16.5 releases. Cisco Bug IDs: CSCvc65866, CSCve77132.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 3.13.0as

cisco ios xe 3.13.0s

cisco ios xe 3.13.1s

cisco ios xe 3.13.2as

cisco ios xe 3.13.2s

cisco ios xe 3.13.3s

cisco ios xe 3.13.4s

cisco ios xe 3.13.5as

cisco ios xe 3.13.5s

cisco ios xe 3.13.6as

cisco ios xe 3.13.6s

cisco ios xe 3.14.0s

cisco ios xe 3.14.1s

cisco ios xe 3.14.2s

cisco ios xe 3.14.3s

cisco ios xe 3.14.4s

cisco ios xe 3.15.0s

cisco ios xe 3.15.1cs

cisco ios xe 3.15.1s

cisco ios xe 3.15.2s

cisco ios xe 3.15.3s

cisco ios xe 3.15.4s

cisco ios xe 3.16.0as

cisco ios xe 3.16.0bs

cisco ios xe 3.16.0cs

cisco ios xe 3.16.0s

cisco ios xe 3.16.1as

cisco ios xe 3.16.1s

cisco ios xe 3.16.2as

cisco ios xe 3.16.2bs

cisco ios xe 3.16.2s

cisco ios xe 3.16.3as

cisco ios xe 3.16.3s

cisco ios xe 3.16.4as

cisco ios xe 3.16.4bs

cisco ios xe 3.16.4cs

cisco ios xe 3.16.4ds

cisco ios xe 3.16.4es

cisco ios xe 3.16.4gs

cisco ios xe 3.16.4s

cisco ios xe 3.16.5as

cisco ios xe 3.16.5bs

cisco ios xe 3.16.5s

cisco ios xe 3.17.0s

cisco ios xe 3.17.1as

cisco ios xe 3.17.1s

cisco ios xe 3.17.2s

cisco ios xe 3.17.3s

cisco ios xe 3.18.0as

cisco ios xe 3.18.0s

cisco ios xe 3.18.0sp

cisco ios xe 3.18.1asp

cisco ios xe 3.18.1bsp

cisco ios xe 3.18.1csp

cisco ios xe 3.18.1gsp

cisco ios xe 3.18.1hsp

cisco ios xe 3.18.1isp

cisco ios xe 3.18.1s

cisco ios xe 3.18.1sp

cisco ios xe 3.18.2asp

cisco ios xe 3.18.2s

cisco ios xe 3.18.2sp

cisco ios xe 16.3.1a

cisco ios xe 16.3.5b

cisco ios xe 16.3.6

cisco ios xe 16.3.7

cisco ios xe 16.3.8

cisco ios xe 16.3.9

cisco ios xe 16.3.10

cisco ios xe 16.3.11

cisco ios xe 16.4.3

cisco ios xe 16.5.1

cisco ios xe 16.9.3a

cisco ios xe 16.9.3s

Vendor Advisories

A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an affected device's operating system The vulnerability exists because an engineering console port is available on the motherboard ...