ID

VAR-201710-0649


CVE

CVE-2017-12271


TITLE

Cisco SPA300 and SPA500 Series IP Phones Cross-Site Request Forgery Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2017-35520 // CNNVD: CNNVD-201710-886

DESCRIPTION

A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCuz88421, CSCuz91356, CSCve56308. Vendors have confirmed this vulnerability Bug ID CSCuz88421 , CSCuz91356 ,and CSCve56308 It is released as.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Other attacks are also possible

Trust: 2.52

sources: NVD: CVE-2017-12271 // JVNDB: JVNDB-2017-009474 // CNVD: CNVD-2017-35520 // BID: 101524 // VULHUB: VHN-102777

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-35520

AFFECTED PRODUCTS

vendor:ciscomodel:spa300scope:lteversion:7.5.5

Trust: 1.0

vendor:ciscomodel:spa500scope:lteversion:7.5.5

Trust: 1.0

vendor:ciscomodel:small business ip phonescope: - version: -

Trust: 0.8

vendor:ciscomodel:spa500 series ip phonesscope: - version: -

Trust: 0.6

vendor:ciscomodel:spa300 series ip phonesscope: - version: -

Trust: 0.6

vendor:ciscomodel:spa300 series ip phonescope:eqversion:7.5.5

Trust: 0.6

vendor:ciscomodel:spa500 series ip phonescope:eqversion:7.5.5

Trust: 0.6

vendor:ciscomodel:spa500 series ip phonesscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:spa300 series ip phonesscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:small business spa500 series ip phonesscope:eqversion:7.5.5

Trust: 0.3

vendor:ciscomodel:small business ip phonesscope:eqversion:7.5.5

Trust: 0.3

vendor:ciscomodel:small business spa500 series ip phones 7.6 sr3scope:neversion: -

Trust: 0.3

vendor:ciscomodel:small business ip phones 7.6 sr3scope:neversion: -

Trust: 0.3

sources: CNVD: CNVD-2017-35520 // BID: 101524 // JVNDB: JVNDB-2017-009474 // CNNVD: CNNVD-201710-886 // NVD: CVE-2017-12271

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-12271
value: HIGH

Trust: 1.0

NVD: CVE-2017-12271
value: HIGH

Trust: 0.8

CNVD: CNVD-2017-35520
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201710-886
value: HIGH

Trust: 0.6

VULHUB: VHN-102777
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-12271
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-35520
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-102777
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-12271
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2017-12271
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2017-35520 // VULHUB: VHN-102777 // JVNDB: JVNDB-2017-009474 // CNNVD: CNNVD-201710-886 // NVD: CVE-2017-12271

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.9

sources: VULHUB: VHN-102777 // JVNDB: JVNDB-2017-009474 // NVD: CVE-2017-12271

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201710-886

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201710-886

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-009474

PATCH

title:cisco-sa-20171018-spaurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-spa

Trust: 0.8

title:Patch for CiscoSPA300 and SPA500SeriesIPPhones Cross-Site Request Forgery Vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/106677

Trust: 0.6

title:Cisco SPA300 and SPA500 Series IP Phones Fixes for cross-site request forgery vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=75868

Trust: 0.6

sources: CNVD: CNVD-2017-35520 // JVNDB: JVNDB-2017-009474 // CNNVD: CNNVD-201710-886

EXTERNAL IDS

db:NVDid:CVE-2017-12271

Trust: 3.4

db:BIDid:101524

Trust: 2.6

db:SECTRACKid:1039621

Trust: 1.7

db:JVNDBid:JVNDB-2017-009474

Trust: 0.8

db:CNNVDid:CNNVD-201710-886

Trust: 0.7

db:CNVDid:CNVD-2017-35520

Trust: 0.6

db:VULHUBid:VHN-102777

Trust: 0.1

sources: CNVD: CNVD-2017-35520 // VULHUB: VHN-102777 // BID: 101524 // JVNDB: JVNDB-2017-009474 // CNNVD: CNNVD-201710-886 // NVD: CVE-2017-12271

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20171018-spa

Trust: 2.6

url:http://www.securityfocus.com/bid/101524

Trust: 1.7

url:http://www.securitytracker.com/id/1039621

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-12271

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-12271

Trust: 0.8

url:http://www.cisco.com

Trust: 0.3

sources: CNVD: CNVD-2017-35520 // VULHUB: VHN-102777 // BID: 101524 // JVNDB: JVNDB-2017-009474 // CNNVD: CNNVD-201710-886 // NVD: CVE-2017-12271

CREDITS

Chris Watts of Tech Analysis.

Trust: 0.3

sources: BID: 101524

SOURCES

db:CNVDid:CNVD-2017-35520
db:VULHUBid:VHN-102777
db:BIDid:101524
db:JVNDBid:JVNDB-2017-009474
db:CNNVDid:CNNVD-201710-886
db:NVDid:CVE-2017-12271

LAST UPDATE DATE

2024-11-23T22:34:28.418000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-35520date:2017-11-30T00:00:00
db:VULHUBid:VHN-102777date:2019-10-09T00:00:00
db:BIDid:101524date:2017-10-18T00:00:00
db:JVNDBid:JVNDB-2017-009474date:2017-11-13T00:00:00
db:CNNVDid:CNNVD-201710-886date:2019-10-17T00:00:00
db:NVDid:CVE-2017-12271date:2024-11-21T03:09:12.393

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-35520date:2017-11-30T00:00:00
db:VULHUBid:VHN-102777date:2017-10-19T00:00:00
db:BIDid:101524date:2017-10-18T00:00:00
db:JVNDBid:JVNDB-2017-009474date:2017-11-13T00:00:00
db:CNNVDid:CNNVD-201710-886date:2017-10-23T00:00:00
db:NVDid:CVE-2017-12271date:2017-10-19T08:29:00.343