CVE-2017-12229 is a critical vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE versions 3.1 through 16.5. This flaw, stemming from insufficient input validation, allows an unauthenticated, remote attacker to bypass authentication to the web UI. With a CVSS score of 9.8 (CRITICAL), a successful exploit grants full access to the affected device's web UI, leading to high confidentiality, integrity, and availability impacts. While there is no known active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community attention with 11 mentions and one media article, indicating its perceived risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.3asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.3as:*:*:*:*:*:*:* | ||
3.2.0jaCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.2.0ja:*:*:*:*:*:*:* | ||
3.2.1xoCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.2.1xo:*:*:*:*:*:*:* | ||
3.4.7asgCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.4.7asg:*:*:*:*:*:*:* | ||
3.6.5beCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.6.5be:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.