CVE-2017-12281 (CNNVD-201711-072)
中文标题:
Cisco Aironet 1800、2800和3800 Series Access Points 安全漏洞
英文标题:
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functio...
漏洞描述
中文描述:
Cisco Aironet 1800、2800和3800 Series Access Points都是美国思科(Cisco)公司的路由器接入设备。 Cisco Aironet 1800、2800和3800 Series Access Points中的Protected Extensible Authentication Protocol (PEAP)功能的实现存在身份验证绕过漏洞。攻击者可利用该漏洞绕过安全限制,连接到受影响的设备上。
英文描述:
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an unauthenticated, adjacent attacker to bypass authentication and connect to an affected device. The vulnerability exists because the affected device uses an incorrect default configuration setting of fail open when running in standalone mode. An attacker could exploit this vulnerability by attempting to connect to an affected device. A successful exploit could allow the attacker to bypass authentication and connect to the affected device. This vulnerability affects Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running a vulnerable software release and use WLAN configuration settings that include FlexConnect local switching and central authentication with MAC filtering. Cisco Bug IDs: CSCvd46314.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | aironet_1800_firmware | - | - | - |
cpe:2.3:o:cisco:aironet_1800_firmware:-:*:*:*:*:*:*:*
|
| cisco | aironet_2800_firmware | - | - | - |
cpe:2.3:o:cisco:aironet_2800_firmware:-:*:*:*:*:*:*:*
|
| cisco | aironet_3800_firmware | - | - | - |
cpe:2.3:o:cisco:aironet_3800_firmware:-:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-12281 |
2025-11-11 15:19:17 | 2025-11-11 07:34:33 |
| NVD | nvd_CVE-2017-12281 |
2025-11-11 14:55:33 | 2025-11-11 07:43:12 |
| CNNVD | cnnvd_CNNVD-201711-072 |
2025-11-11 15:09:55 | 2025-11-11 07:53:22 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-201711-072
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']