First published: Thu Jan 26 2017(Updated: )
A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated, remote attacker to view confidential information that is displayed without authenticating to the device. Affected Products: This vulnerability affects Cisco IOS Software and Cisco IOx Software running on IR829, IR809, IE4K, and CGR1K platforms. More Information: CSCvb20897. Known Affected Releases: 1.0(0).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOx | =1.0\(0\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3805 is rated as a high severity vulnerability due to its potential to allow unauthorized access to confidential information.
To mitigate CVE-2017-3805, ensure you apply the relevant Cisco IOS Software security updates and patches provided by Cisco.
CVE-2017-3805 affects devices running specific versions of Cisco IOS and Cisco IOx Software that have the web-based management interface enabled.
Yes, CVE-2017-3805 can be exploited by unauthenticated remote attackers, allowing them to view confidential information.
No, authentication is not required to exploit CVE-2017-3805, making it particularly concerning.