CVE-2017-12350Patch(cisco / umbrella_virtual_appliance)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco umbrella_virtual_appliance systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of default, static user credentials for an affected virtual appliance. An attacker could exploit this vulnerability by using the hypervisor console to connect locally to an affected system and then using the static credentials to log in to an affected virtual appliance. A successful exploit could allow the attacker to log in to the affected appliance with root privileges. Cisco Bug IDs: CSCvg31220.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • umbrella_virtual_appliance

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
umbrella_virtual_appliance

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-22: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-22: 106-22
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2017-12350 (CVSS 8.2) - Cisco Umbrella Insights Virtual Appliances ≤2.1.0 contain default static credentials allowing local authenticated attackers to gain root access. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/qmLqJ07f4T

    Post summary

    The tweet highlights a high‑severity CVE where default credentials enable local privilege escalation in Cisco Umbrella Insights and urges users to apply a patch.

    0000058
    49 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoumbrella_virtual_appliance---

Explore more