CVE-2017-12317

The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker could exploit this vulnerability by gaining local, administrative access to a Windows host and stopping the Cisco AMP for Endpoints service. Cisco Bug IDs: CSCvg42904.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
ciscoadvanced_malware_protection
3.1\(10\)
ciscoadvanced_malware_protection
3.1\(15\)
ciscoadvanced_malware_protection
4.0\(0\)
ciscoadvanced_malware_protection
4.0\(1\)
ciscoadvanced_malware_protection
4.0\(2\)
ciscoadvanced_malware_protection
4.1\(0\)
ciscoadvanced_malware_protection
4.1\(1\)
ciscoadvanced_malware_protection
4.1\(4\)
ciscoadvanced_malware_protection
4.2\(0\)
ciscoadvanced_malware_protection
4.2\(1\)
ciscoadvanced_malware_protection
4.3\(0\)
ciscoadvanced_malware_protection
4.3\(1\)
ciscoadvanced_malware_protection
4.4\(0\)
ciscoadvanced_malware_protection
4.4\(1\)
ciscoadvanced_malware_protection
4.4\(2\)
ciscoadvanced_malware_protection
4.4\(4\)
ciscoadvanced_malware_protection
5.0\(1\)
ciscoadvanced_malware_protection
5.0\(3\)
ciscoadvanced_malware_protection
5.0\(5\)
ciscoadvanced_malware_protection
5.0\(7\)
ciscoadvanced_malware_protection
5.0\(9\)
ciscoadvanced_malware_protection
5.1\(1\)
ciscoadvanced_malware_protection
5.1\(3\)
ciscoadvanced_malware_protection
5.1\(5\)
ciscoadvanced_malware_protection
5.1\(7\)
ciscoadvanced_malware_protection
5.1\(9\)
ciscoadvanced_malware_protection
5.1\(11\)
ciscoadvanced_malware_protection
5.1\(13\)
ciscoadvanced_malware_protection
6.0\(1\)
𝑥
= Vulnerable software versions