Security readout for executives and security teams
Plain-English summary
This flaw affected Circle with Disney’s cloud routing infrastructure. A malicious Internet-reachable packet could cause Circle’s cloud to route traffic to an arbitrary Circle device, creating potential confidentiality, integrity, and availability impact. The source bundle names Circle firmware 2.0.1; it does not provide current patch, mitigation, or exploitation evidence.
Executive priority
Treat as urgent where affected devices still exist, because impact is potentially severe and Internet-reachable. Priority drops if asset inventory confirms no Circle firmware 2.0.1 devices or dependent cloud service exposure.
Technical view
CVE-2017-12085 is a network-triggerable routing vulnerability in Circle Media Circle firmware 2.0.1 and associated Circle with Disney cloud infrastructure. CVSS v3.0 is 9.0, with no privileges or user interaction required, high confidentiality, integrity, and availability impact, scope changed, and high attack complexity.
Likely exposure
Exposure appears limited to organizations or users that deployed Circle with Disney or Circle Media Circle devices running firmware 2.0.1 and relying on the affected cloud routing path. The bundle does not identify other versions, CPEs, or successor products.
Exploitation context
The CVE states an attacker only needs Internet connectivity, but attack complexity is high. The bundle does not include CISA KEV status or any cited evidence of active exploitation, public exploit code, or observed attacks.
Researcher notes
Evidence is sparse outside the CVE and Talos reference. The described primitive is cloud-assisted routing of crafted packets to arbitrary Circle devices. Do not assume affected versions beyond firmware 2.0.1 without vendor or Talos confirmation.
Mitigation direction
- Identify any Circle with Disney or Circle Media Circle firmware 2.0.1 assets.
- Check Circle Media or vendor guidance for fixed firmware or retirement instructions.
- Remove unsupported affected devices from production or sensitive networks.
- Restrict affected device network access where continued operation is unavoidable.
Validation and detection
- Inventory networks for Circle with Disney or Circle Media Circle devices.
- Confirm firmware versions and flag firmware 2.0.1 as affected.
- Review device placement and whether sensitive traffic or users depend on it.
- Track vendor advisories because the bundle does not name a patch.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2017-12085 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Critical
- CVSS
- 9 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H2.26Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
9CriticalVector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0437CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
