CVE-2017-12337
Description
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration Deployment (PCD) migration is performed on an affected device. When a refresh upgrade or PCD migration is completed successfully, an engineering flag remains enabled and could allow root access to the device with a known password. If the vulnerable device is subsequently upgraded using the standard upgrade method to an Engineering Special Release, service update, or a new major release of the affected product, this vulnerability is remediated by that action. Note: Engineering Special Releases that are installed as COP files, as opposed to the standard upgrade method, do not remediate this vulnerability. An attacker who can access an affected device over SFTP while it is in a vulnerable state could gain root access to the device. This access could allow the attacker to compromise the affected system completely. Cisco Bug IDs: CSCvg22923, CSCvg55112, CSCvg55128, CSCvg55145, CSCvg58619, CSCvg64453, CSCvg64456, CSCvg64464, CSCvg64475, CSCvg68797.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Improper Authentication
DraftCommon Consequences
Applicable Platforms
Unity Connection by Cisco
cpe:2.3:a:cisco:unity_connection:-:*:*:*:*:*:*:*
Unified Communications Manager Im And Presence Service by Cisco
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:-:*:*:*:*:*:*:*
Unified Intelligence Center by Cisco
cpe:2.3:a:cisco:unified_intelligence_center:-:*:*:*:*:*:*:*
Unified Communications Manager by Cisco
cpe:2.3:a:cisco:unified_communications_manager:-:*:*:*:*:*:*:*
Unified Contact Center Express by Cisco
cpe:2.3:a:cisco:unified_contact_center_express:-:*:*:*:*:*:*:*
Socialminer by Cisco
cpe:2.3:a:cisco:socialminer:-:*:*:*:*:*:*:*
Prime License Manager by Cisco
cpe:2.3:a:cisco:prime_license_manager:-:*:*:*:*:*:*:*
Unified Communications Manager by Cisco
cpe:2.3:a:cisco:unified_communications_manager:-:*:*:*:session_management:*:*:*
Finesse by Cisco
cpe:2.3:a:cisco:finesse:-:*:*:*:*:*:*:*
Mediasense by Cisco
cpe:2.3:a:cisco:mediasense:-:*:*:*:*:*:*:*
Emergency Responder by Cisco
cpe:2.3:a:cisco:emergency_responder:-:*:*:*:*:*:*:*
Hosted Collaboration Solution by Cisco
cpe:2.3:a:cisco:hosted_collaboration_solution:-:*:*:*:*:*:*:*