cisco-sa-20171020-ampfe
Cisco AMP for Endpoints Static Key Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
On October 20th, 2017, Cisco PSIRT was notified by the internal product team of a security vulnerability in the Cisco AMP For Endpoints application that would allow an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker could exploit this vulnerability by gaining local, administrative access to a Windows host and stopping the Cisco AMP for Endpoints service. Workarounds that address this vulnerability are available.
| Product | CVE |
|---|---|
| Cisco AMP for Endpoints | CVE-2017-12317 |