Vulnslist

find the latest Cisco vulnerabilities

Cisco Spark Board Upgrade Signature Verification Bypass Vulnerability

cisco-sa-20171115-spark · Medium · Published · Updated

A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade package. The vulnerability is due to insufficient upgrade package validation. An attacker could exploit this vulnerability by providing the upgrade process with an upgrade package that the attacker controls. An exploit could allow the attacker to install custom firmware to the Spark Board. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171115-spark

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2017-12306
Cisco Bug IDsCSCvf84502
CVSS ScoreBase 4.4
Base 4.4 CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Webex Teams, Cisco Webex App

Related Products

Product CVE Evidence
Cisco Webex Teams CVE-2017-12306 Cisco OpenVuln
Cisco Webex App CVE-2017-12306 Cisco OpenVuln