CVE-2017-12213 (CNNVD-201709-232)
中文标题:
Cisco Catalyst 4000 Series Switches IOS XE Software 安全漏洞
英文标题:
A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on...
漏洞描述
中文描述:
Cisco Catalyst 4000 Series Switches是美国思科(Cisco)公司的一款4000系列交换机设备。IOS XE Software是其中的一个网络设备开发的操作系统。 Cisco Catalyst 4000 Series Switches中的IOS XE Software的动态访问列表(ACL)存在安全漏洞。物理位置临近的攻击者可利用该漏洞绕过802.1x身份验证,造成受影响的端口无法打开,并向受影响交换机端口的默认VLAN传输流量。
英文描述:
A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches could allow an unauthenticated, adjacent attacker to cause dynamic ACL assignment to fail and the port to fail open. This could allow the attacker to pass traffic to the default VLAN of the affected port. The vulnerability is due to an uncaught error condition that may occur during the reassignment of the auth-default-ACL dynamic ACL to a switch port after 802.1x authentication fails. A successful exploit of this issue could allow a physically adjacent attacker to bypass 802.1x authentication and cause the affected port to fail open, allowing the attacker to pass traffic to the default VLAN of the affected switch port. Cisco Bug IDs: CSCvc72751.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | ios_xe | - | - | - |
cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-12213 |
2025-11-11 15:19:17 | 2025-11-11 07:34:33 |
| NVD | nvd_CVE-2017-12213 |
2025-11-11 14:55:31 | 2025-11-11 07:43:12 |
| CNNVD | cnnvd_CNNVD-201709-232 |
2025-11-11 15:09:53 | 2025-11-11 07:53:17 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-201709-232
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 4.3
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']