CVE-2017-12228 is a medium-severity vulnerability affecting Cisco IOS and IOS XE, specifically within the Network Plug and Play application. It allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data due to insufficient certificate validation. An attacker could exploit this by supplying a crafted certificate, enabling man-in-the-middle attacks to decrypt confidential user information. While the CVSS score is 5.9 (MEDIUM) with high confidentiality impact, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(4\)ec2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(4\)ec2:*:*:*:*:*:*:* | ||
15.2\(4\)gcCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(4\)gc:*:*:*:*:*:*:* | ||
15.2\(4\)gc1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(4\)gc1:*:*:*:*:*:*:* | ||
12.4\(25e\)jao3aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.4\(25e\)jao3a:*:*:*:*:*:*:* | ||
12.4\(25e\)jao20sCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.4\(25e\)jao20s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.