6.7
CVSSv3

CVE-2017-12317

Published: 22/10/2017 Updated: 09/10/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Cisco AMP For Endpoints application allows an authenticated, local malicious user to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker could exploit this vulnerability by gaining local, administrative access to a Windows host and stopping the Cisco AMP for Endpoints service. Cisco Bug IDs: CSCvg42904.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco advanced malware protection 3.1\\(10\\)

cisco advanced malware protection 4.1\\(4\\)

cisco advanced malware protection 4.2\\(1\\)

cisco advanced malware protection 5.0\\(1\\)

cisco advanced malware protection 5.0\\(5\\)

cisco advanced malware protection 5.1\\(13\\)

cisco advanced malware protection 5.1\\(5\\)

cisco advanced malware protection 4.0\\(0\\)

cisco advanced malware protection 4.0\\(1\\)

cisco advanced malware protection 4.0\\(2\\)

cisco advanced malware protection 4.1\\(0\\)

cisco advanced malware protection 4.1\\(1\\)

cisco advanced malware protection 5.0\\(7\\)

cisco advanced malware protection 5.0\\(9\\)

cisco advanced malware protection 5.1\\(1\\)

cisco advanced malware protection 5.1\\(11\\)

cisco advanced malware protection 4.3\\(1\\)

cisco advanced malware protection 4.4\\(0\\)

cisco advanced malware protection 4.4\\(1\\)

cisco advanced malware protection 4.4\\(2\\)

cisco advanced malware protection 5.1\\(9\\)

cisco advanced malware protection 6.0\\(1\\)

cisco advanced malware protection 3.1\\(15\\)

cisco advanced malware protection 4.2\\(0\\)

cisco advanced malware protection 4.3\\(0\\)

cisco advanced malware protection 4.4\\(4\\)

cisco advanced malware protection 5.0\\(3\\)

cisco advanced malware protection 5.1\\(3\\)

cisco advanced malware protection 5.1\\(7\\)

Vendor Advisories

On October 20th, 2017, Cisco PSIRT was notified by the internal product team of a security vulnerability in the Cisco AMP For Endpoints application that would allow an authenticated, local attacker to access a static key value stored in the local application software The vulnerability is due to the use of a static key value stored in the applicat ...