当前位置:网站首页>云安全日报220707:思科Expressway系列和网真视频通信服务器发现远程攻击漏洞,需要尽快升级
云安全日报220707:思科Expressway系列和网真视频通信服务器发现远程攻击漏洞,需要尽快升级
2022-07-07 16:23:00 【TechWeb】
7月7日,思科发布了安全更新,修复了思科Expressway系列和网真视频通信服务器发现的远程攻击漏洞。以下是漏洞详情:
漏洞详情
来源:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-overwrite-3buqW8LH
1.CVE-2022-20812 CVSS评分:9.0 严重程度:重要
Cisco Expressway 系列和 Cisco TelePresence VCS 的集群数据库 API 中的一个漏洞可能允许经过身份验证的远程攻击者对应用程序具有管理员读写权限,以对受影响的设备进行绝对路径遍历攻击并覆盖底层操作系统上的文件根用户。
此漏洞是由于用户提供的命令参数的输入验证不足。攻击者可以通过以管理读写用户身份向系统进行身份验证并将精心设计的输入提交给受影响的命令来利用此漏洞。成功的利用可能允许攻击者以root身份覆盖底层操作系统上的任意文件用户。
2.CVE-2022-20813 CVSS评分:7.4 严重程度:高
Cisco Expressway 系列和 Cisco TelePresence VCS 证书验证中的一个漏洞可能允许未经身份验证的远程攻击者未经授权访问敏感数据。
此漏洞是由于不正确的证书验证造成的。攻击者可以通过使用中间人技术来拦截设备之间的流量,然后使用精心制作的证书来模拟端点来利用此漏洞。成功的利用可能允许攻击者以明文形式查看截获的流量或更改流量的内容。
受影响产品
上述漏洞影响使用默认配置的Cisco Expressway系列和Cisco TelePresence VCS 14.0及以下版本。
解决方案
Cisco Expressway系列和Cisco TelePresence VCS升级至14.0.7版本可修复
查看更多漏洞信息 以及升级请访问官网:
https://tools.cisco.com/security/center/publicationListing.x
边栏推荐
- Use onedns to perfectly solve the optimization problem of office network
- 原生js验证码
- Understanding of 12 methods of enterprise management
- Tips of this week 141: pay attention to implicit conversion to bool
- How to clean when win11 C disk is full? Win11 method of cleaning C disk
- Target detection 1 -- actual operation of Yolo data annotation and script for converting XML to TXT file
- Management by objectives [14 of management]
- 回归测试的分类
- 仿今日头条APP顶部点击可居中导航
- 现在网上期货开户安全吗?国内有多少家正规的期货公司?
猜你喜欢
![[principle and technology of network attack and Defense] Chapter 6: Trojan horse](/img/2f/bd35ca141fad5c85f78fd6340ada1d.png)
[principle and technology of network attack and Defense] Chapter 6: Trojan horse

Summary of debian10 system problems

In depth understanding of USB communication protocol

Some key points in the analysis of spot Silver

【C语言】字符串函数

Deep learning - make your own dataset

More than 10000 units were offline within ten days of listing, and the strength of Auchan Z6 products was highly praised

The report of the state of world food security and nutrition was released: the number of hungry people in the world increased to 828million in 2021

现货白银分析中的一些要点

Ansible learning summary (9) -- ansible loop, condition judgment, trigger, processing failure and other task control use summary
随机推荐
Debian10 compile and install MySQL
Classification of regression tests
手机版像素小鸟游js戏代码
A few simple steps to teach you how to see the K-line diagram
Summary of debian10 system problems
Tips of this week 135: test the contract instead of implementation
Afghan interim government security forces launched military operations against a hideout of the extremist organization "Islamic state"
4种常见的缓存模式,你都知道吗?
Cf:c. factors and powers of two [DP + sort + Select Board + select several numbers equal to the minimum number of known sums]
Tips for this week 134: make_ Unique and private constructors
Deep learning - make your own dataset
Deep learning machine learning various data sets summary address
Slider plug-in for swiper left and right switching
Yarn capacity scheduler (ultra detailed interpretation)
nest. Database for getting started with JS
Hutool - 轻量级 DB 操作解决方案
TaffyDB开源的JS数据库
The report of the state of world food security and nutrition was released: the number of hungry people in the world increased to 828million in 2021
云景网络科技面试题【杭州多测师】【杭州多测师_王sir】
上市十天就下线过万台,欧尚Z6产品实力备受点赞