CVE Database
/

CVE-2017-12223

Back to search

CVE-2017-12223

Published: Sep 7, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the ROM Monitor (ROMMON) code of Cisco IR800 Integrated Services Router Software could allow an unauthenticated, local attacker to boot an unsigned Hypervisor on an affected device and compromise the integrity of the system. The vulnerability is due to insufficient sanitization of user input. An attacker who can access an affected router via the console could exploit this vulnerability by entering ROMMON mode and modifying ROMMON variables. A successful exploit could allow the attacker to execute arbitrary code and install a malicious version of Hypervisor firmware on an affected device. Cisco Bug IDs: CSCvb44027.

VendorProductVersions

n/a

Cisco IR800 Integrated Services Router

affected
Cisco IR800 Integrated Services Router

Weaknesses (CWE)

References

1039275
vdb-entry
x_refsource_SECTRACK
100689
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now