Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-12340

EPSS 0.13% · P32
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-12340

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allow an authenticated, local attacker to access the Bash shell of an affected device's operating system, even if the Bash shell is disabled on the system. The vulnerability is due to insufficient sanitization of user-supplied parameters that are passed to certain functions of the Python scripting sandbox of the affected system. An attacker could exploit this vulnerability to escape the scripting sandbox and enter the Bash shell of the operating system with the privileges of the authenticated user for the affected system. To exploit this vulnerability, the attacker must have local access to the affected system and be authenticated to the affected system with administrative or Python execution privileges. Cisco Bug IDs: CSCvd86513.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
访问控制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款Cisco产品Cisco NX-OS System Software 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco MDS Multilayer Director Switches、Cisco Nexus 7000 Series Switches和Cisco Nexus 7700 Series Switches都是美国思科(Cisco)公司的交换机产品。NX-OS System Software是使用在其中的一套操作系统。 多款Cisco产品中的Cisco NX-OS System Software存在安全漏洞,该漏洞源于程序没有充分过滤用户提交的参数。本地攻击者可利用该漏洞绕过脚本沙盒并以已认证用户权限进
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches -

II. Public POCs for CVE-2017-12340

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-12340

登录查看更多情报信息。

Same Patch Batch · n/a · 2017-11-30 · 56 CVEs total

CVE-2017-12359多款Cisco产品WebEx Advanced Recording Format Player 缓冲区错误漏洞
CVE-2017-14198Squiz Matrix 安全漏洞
CVE-2017-12370多款Cisco产品WebEx Recording Format Player和Advanced Recording Format Player 安全漏洞
CVE-2017-14196Squiz Matrix File Bridge插件路径遍历漏洞
CVE-2017-12372多款Cisco产品WebEx Recording Format Player和Advanced Recording Format Player 安全漏洞
CVE-2017-12371多款Cisco产品WebEx Recording Format Player和Advanced Recording Format Player 安全漏洞
CVE-2017-14197Squiz Matrix Matrix WYSIWYG插件跨站脚本漏洞
CVE-2017-12362Cisco Meeting Server 安全漏洞
CVE-2017-12361Cisco Jabber for Windows 信息泄露漏洞
CVE-2017-12360Cisco WebEx Business Suite meeting site和Cisco WebEx Meetings site WebEx Recording Format P
CVE-2017-12363Cisco WebEx Meeting Server 安全漏洞
CVE-2017-12358Cisco Jabber for Windows、Mac、Android和iOS Cisco Jabber 跨站脚本漏洞
CVE-2017-12357Cisco Unified Communications Manager 跨站脚本漏洞
CVE-2017-12356Cisco Jabber for Windows、Mac、Android和iOS Cisco Jabber 跨站脚本漏洞
CVE-2017-12355Cisco IOS XR Software 安全漏洞
CVE-2017-12354Cisco Secure Access Control System 信息泄露漏洞
CVE-2017-12353Cisco Email Security Appliance Cisco AsyncOS Software Multipurpose Internet Mail Extension
CVE-2017-12352Cisco Application Policy Infrastructure Controller 命令注入漏洞
CVE-2017-12351多款Cisco产品NX-OS System Software 安全漏洞
CVE-2017-12349Cisco UCS Central Software 安全漏洞

Showing top 20 of 56 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-12340

No comments yet


Leave a comment