Junglewise Threat Intelligence

CVE-2017-3805: Cisco IOS and IOx information disclosure in web management interface

CVE-2017-3805 · Severity: medium · CVSS 5.3 · Published 2017-01-26

Technologies: Cisco IOS. Vendors: Cisco.

Executive brief

A vulnerability in the web management interface of certain Cisco networking devices could allow an unauthorized person to view sensitive system information. This affects industrial and ruggedized hardware, such as the IR829 and CGR1K platforms. An attacker could use this information to better understand the network's configuration and plan further attacks, though they cannot directly take control of the device through this specific flaw.

Technical details

An information disclosure vulnerability exists in the web-based management interface of Cisco IOS and Cisco IOx Software due to improper input validation of requested HTTP URLs. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to an affected device. Successful exploitation allows the attacker to bypass authentication checks for specific pages, granting access to confidential information intended only for authorized administrators. This vulnerability specifically impacts Cisco IR829, IR809, IE4K, and CGR1K platforms. Cisco has addressed this issue in bug ID CSCvb20897.

Affected products

  • Cisco IOS 1.0(0)
  • Cisco IOx 1.0(0)

Timeline

  • 2017-01-18: advisory: Initial public release by Cisco
  • 2017-01-26: disclosed: NVD publication date

References

Related threats