CVE-2017-12306

CVE-2017-12306

A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade package, aka Signature Verification Bypass. The vulnerability is due to insufficient upgrade package validation. An attacker could exploit this vulnerability by providing the upgrade process with an upgrade package that the attacker controls. An exploit could allow the attacker to install custom firmware to the Spark Board. Cisco Bug IDs: CSCvf84502.

Source: CVE-2017-12306

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다