Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-12351

EPSS 0.07% · P20
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-12351

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outside the scope of the guest shell container. An attacker would need valid administrator credentials to perform this attack. The vulnerability is due to insufficient internal security measures in the guest shell feature. An attacker could exploit this vulnerability by sending or receiving packets on the device-internal network outside of the guest shell container, aka "Unauthorized Internal Interface Access." This vulnerability affects the following products running Cisco NX-OS System Software: Nexus 3000 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvf33038.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
权限、特权和访问控制
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款Cisco产品NX-OS System Software 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Nexus 3000 Series Switches等都是美国思科(Cisco)公司的产品。Cisco Nexus 3000 Series Switches是一款3000系列交换机。Nexus 9500 R-Series Line Cards是一款9500R系列线路卡。NX-OS System Software是一套运行在其中的操作系统。 多款Cisco产品中的NX-OS System Software的guest shell功能存在安全漏洞,该漏洞源于内部安全措施不足。本地攻击者可借助有效的
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Cisco NX-OS Cisco NX-OS -

II. Public POCs for CVE-2017-12351

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-12351

登录查看更多情报信息。

Same Patch Batch · n/a · 2017-11-30 · 56 CVEs total

CVE-2017-12359多款Cisco产品WebEx Advanced Recording Format Player 缓冲区错误漏洞
CVE-2017-14198Squiz Matrix 安全漏洞
CVE-2017-12370多款Cisco产品WebEx Recording Format Player和Advanced Recording Format Player 安全漏洞
CVE-2017-14196Squiz Matrix File Bridge插件路径遍历漏洞
CVE-2017-12372多款Cisco产品WebEx Recording Format Player和Advanced Recording Format Player 安全漏洞
CVE-2017-12371多款Cisco产品WebEx Recording Format Player和Advanced Recording Format Player 安全漏洞
CVE-2017-14197Squiz Matrix Matrix WYSIWYG插件跨站脚本漏洞
CVE-2017-12362Cisco Meeting Server 安全漏洞
CVE-2017-12361Cisco Jabber for Windows 信息泄露漏洞
CVE-2017-12360Cisco WebEx Business Suite meeting site和Cisco WebEx Meetings site WebEx Recording Format P
CVE-2017-12363Cisco WebEx Meeting Server 安全漏洞
CVE-2017-12358Cisco Jabber for Windows、Mac、Android和iOS Cisco Jabber 跨站脚本漏洞
CVE-2017-12357Cisco Unified Communications Manager 跨站脚本漏洞
CVE-2017-12356Cisco Jabber for Windows、Mac、Android和iOS Cisco Jabber 跨站脚本漏洞
CVE-2017-12355Cisco IOS XR Software 安全漏洞
CVE-2017-12354Cisco Secure Access Control System 信息泄露漏洞
CVE-2017-12353Cisco Email Security Appliance Cisco AsyncOS Software Multipurpose Internet Mail Extension
CVE-2017-12352Cisco Application Policy Infrastructure Controller 命令注入漏洞
CVE-2017-12349Cisco UCS Central Software 安全漏洞
CVE-2017-12348Cisco UCS Central Software 跨站脚本漏洞

Showing top 20 of 56 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-12351

No comments yet


Leave a comment