CVE-2017-3805
A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated, remote attacker to view confidential information that is displayed without authenticating to the device.
Does this matter?
Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated, remote attacker to view confidential information that is displayed without authenticating to the device. Affected Products: This vulnerability affects Cisco IOS Software and Cisco IOx Software running on IR829, IR809, IE4K, and CGR1K platforms. More Information: CSCvb20897. Known Affected Releases: 1.0(0).
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cisco/iox
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/95644Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037654
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-iosVendor Advisory
- http://www.securityfocus.com/bid/95644Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037654
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-iosVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.