Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-3852

EPSS 0.79% · P74
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-3852

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual instance running on the affected device. The vulnerability is due to insufficient input validation of user-supplied application packages. An attacker who can upload a malicious package within Cisco IOx could exploit the vulnerability to modify arbitrary files. The impacts of a successful exploit are limited to the scope of the virtual instance and do not impact the router that is hosting Cisco IOx. Cisco IOx Releases 1.0.0.0 and 1.1.0.0 are vulnerable. Cisco Bug IDs: CSCuy52317.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco IOx Cisco Application-hosting Framework 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco IOx是美国思科(Cisco)公司的一套为思科物联网网络基础设施(Cisco路由器、交换机等)提供统一托管功能的应用程序。Cisco Application-hosting Framework(CAF)是其中的一个应用程序托管框架组件。 Cisco IOx 1.0.0.0和1.1.0.0版本的CAF组件存在安全漏洞,该漏洞源于程序没有充分验证用户提供的输入数据。远程攻击者可通过上传恶意的数据包利用该漏洞写入或修改任意文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Cisco Application-Hosting Framework Cisco Application-Hosting Framework -

II. Public POCs for CVE-2017-3852

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-3852

登录查看更多情报信息。

Same Patch Batch · n/a · 2017-03-22 · 29 CVEs total

CVE-2017-7226GNU Binutils 缓冲区错误漏洞
CVE-2017-7222MantisBT 跨站脚本漏洞
CVE-2017-5874D-Link DIR-600M Rev. Cx 跨站请求伪造漏洞
CVE-2017-6971AlienVault USM、OSSIM和NfSen 安全漏洞
CVE-2017-6970AlienVault USM、OSSIM和NfSen 安全漏洞
CVE-2014-9840ImageMagick 安全漏洞
CVE-2014-9839ImageMagick 安全漏洞
CVE-2014-9838ImageMagick 安全漏洞
CVE-2014-9836ImageMagick 安全漏洞
CVE-2014-9835ImageMagick 缓冲区错误漏洞
CVE-2014-9834ImageMagick 缓冲区错误漏洞
CVE-2014-9833ImageMagick 缓冲区错误漏洞
CVE-2014-9832ImageMagick 缓冲区错误漏洞
CVE-2017-7227GNU Binutils 缓冲区错误漏洞
CVE-2017-6972AlienVault USM、OSSIM和NfSen 安全漏洞
CVE-2017-7225GNU Binutils 安全漏洞
CVE-2017-7224GNU Binutils 安全漏洞
CVE-2017-7223GNU Binutils 安全漏洞
CVE-2017-5673Joomla! Kunena组件跨站脚本漏洞
CVE-2017-7231pngdefry 缓冲区错误漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-3852

No comments yet


Leave a comment