First published: Tue Nov 07 2017(Updated: )
An exploitable information disclosure vulnerability exists in the apid daemon of the Circle with Disney running firmware 2.0.1. A specially crafted set of packets can make the Disney Circle dump strings from an internal database into an HTTP response. An attacker needs network connectivity to the Internet to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Meetcircle Circle With Disney Firmware | =2.0.1 | |
Meetcircle Circle With Disney |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12083 is classified as an information disclosure vulnerability.
To mitigate CVE-2017-12083, update your Circle with Disney device to the latest firmware version.
CVE-2017-12083 specifically affects the Circle with Disney firmware version 2.0.1.
Yes, CVE-2017-12083 can be exploited by an attacker with network connectivity to the vulnerable device.
CVE-2017-12083 can result in the disclosure of strings from an internal database through an HTTP response.