CVE-2017-12317: Medium severity cisco advanced malware protection for endpoints vulnerability
The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker could exploit this vulnerability by gaining local, administrative access to a Windows host and stopping the Cisco AMP for Endpoints service. Cisco Bug IDs: CSCvg42904.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12317?
The severity of CVE-2017-12317 is classified as medium.
How do I fix CVE-2017-12317?
To fix CVE-2017-12317, upgrade to the latest version of Cisco AMP for Endpoints that addresses this vulnerability.
Who is affected by CVE-2017-12317?
CVE-2017-12317 affects specific versions of Cisco Advanced Malware Protection for Endpoints, including 3.1(10), 3.1(15), and various 4.0 and 5.0 versions.
What kind of attacks can occur due to CVE-2017-12317?
An attacker can exploit CVE-2017-12317 to access a static key value which may lead to unauthorized access to sensitive information.
Is authentication required to exploit CVE-2017-12317?
Yes, an authenticated, local attacker is needed to exploit CVE-2017-12317.