CVE-2017-12317
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
22/10/2017
Last modified:
20/04/2025
Description
The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker could exploit this vulnerability by gaining local, administrative access to a Windows host and stopping the Cisco AMP for Endpoints service. Cisco Bug IDs: CSCvg42904.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:advanced_malware_protection:3.1\(10\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:3.1\(15\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.0\(0\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.0\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.0\(2\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.1\(0\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.1\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.1\(4\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.2\(0\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.2\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.3\(0\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.3\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.4\(0\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.4\(1\):*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:advanced_malware_protection:4.4\(2\):*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



