CVE-2017-3852: Input Validation
A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual instance running on the affected device. The vulnerability is due to insufficient input validation of user-supplied application packages. An attacker who can upload a malicious package within Cisco IOx could exploit the vulnerability to modify arbitrary files. The impacts of a successful exploit are limited to the scope of the virtual instance and do not impact the router that is hosting Cisco IOx. Cisco IOx Releases 1.0.0.0 and 1.1.0.0 are vulnerable. Cisco Bug IDs: CSCuy52317.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco IOxto a version that resolves this vulnerability.Fixed in 1.0.0.0 - Upgrade
Upgrade
Cisco IOxto a version that resolves this vulnerability.Fixed in 1.1.0.0 - Compensating control
Limit or prevent upload of application packages to Cisco IOx (e.g., only allow trusted packages/users) to reduce exposure to authenticated remote attackers exploiting CSCuy52317.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3852?
CVE-2017-3852 has a medium severity rating that indicates a moderate risk for affected systems.
How do I fix CVE-2017-3852?
To fix CVE-2017-3852, apply the recommended patches provided by Cisco for the affected IOx versions.
Who is affected by CVE-2017-3852?
CVE-2017-3852 affects devices running Cisco IOx version 1.1(0) and 1.1.0.
What type of attackers can exploit CVE-2017-3852?
CVE-2017-3852 can be exploited by authenticated remote attackers with access to the affected devices.
What actions can be taken by exploiting CVE-2017-3852?
Exploitation of CVE-2017-3852 allows attackers to write or modify arbitrary files in the virtual instance of the affected device.