CVE Database
/

CVE-2017-12306

Back to search

CVE-2017-12306

Published: Nov 16, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade package, aka Signature Verification Bypass. The vulnerability is due to insufficient upgrade package validation. An attacker could exploit this vulnerability by providing the upgrade process with an upgrade package that the attacker controls. An exploit could allow the attacker to install custom firmware to the Spark Board. Cisco Bug IDs: CSCvf84502.

VendorProductVersions

n/a

Cisco Spark Board

affected
Cisco Spark Board

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2017-12306 - Security Vulnerability | QwikSec