CVE-2017-12230 describes a privilege escalation vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2. Specifically, incorrect default permission settings for new users created via the web UI allow an authenticated, remote attacker to elevate their privileges on affected devices where the HTTP Server feature is enabled. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating a high-impact threat. An attacker can exploit this with low complexity by simply creating a new user through the web UI and logging in, leading to full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation (not in KEV), no public exploit code (Metasploit, Nuclei, ExploitDB), and a low EPSS score, the vulnerability has received some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.2.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.