Local Access Vulnerability in Cisco AMP for Endpoints Application
CVE-2017-12317

6.7MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
22 October 2017

Summary

The Cisco AMP for Endpoints application contains a vulnerability that permits authenticated local attackers to access a static key value embedded within the application software. This static key is utilized for encrypting the connector protection password, creating a security risk. An attacker with local administrative rights can exploit this vulnerability by stopping the Cisco AMP for Endpoints service, thereby potentially compromising sensitive information. To safeguard against this issue, it is crucial for users to maintain updated software versions and manage local access permissions effectively.

Affected Version(s)

Cisco AMP for Endpoints Cisco AMP for Endpoints

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.