当前位置:网站首页>Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
2022-07-07 18:39:00 【TechWeb】
7 month 7 Japan , Cisco has released a security update , Fixed Cisco Expressway Series and telepresence video communication server . Here are the details of the vulnerability :
Vulnerability Details
source :https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-overwrite-3buqW8LH
1.CVE-2022-20812 CVSS score :9.0 severity : important
Cisco Expressway Series and Cisco TelePresence VCS Cluster database for API A vulnerability in may allow an authenticated remote attacker to have administrator read and write access to the application , To carry out absolute path traversal attack on the affected devices and overwrite the file root user on the underlying operating system .
This vulnerability is due to insufficient input validation of user supplied command parameters . An attacker can exploit this vulnerability by authenticating to the system as an administrative read-write user and submitting carefully designed input to the affected command . Successful exploitation may allow an attacker to root Identity covers any file user on the underlying operating system .
2.CVE-2022-20813 CVSS score :7.4 severity : high
Cisco Expressway Series and Cisco TelePresence VCS A vulnerability in certificate validation may allow unauthenticated remote attackers unauthorized access to sensitive data .
This vulnerability is caused by incorrect certificate validation . Attackers can intercept traffic between devices by using man in the middle Technology , Then use the crafted certificate to simulate the endpoint to exploit this vulnerability . Successful exploitation may allow attackers to view the intercepted traffic or change the content of the traffic in clear text .
Affected products
The above vulnerability affects those using the default configuration Cisco Expressway Series and Cisco TelePresence VCS 14.0 Up to .
Solution
Cisco Expressway Series and Cisco TelePresence VCS To upgrade to 14.0.7 Version repairable
View more vulnerability information And upgrade, please visit the official website :
https://tools.cisco.com/security/center/publicationListing.x
边栏推荐
- 线程池的拒绝策略
- Chapter 1 Introduction to CRM core business
- Ten thousand words nanny level long article -- offline installation guide for datahub of LinkedIn metadata management platform
- 清华、剑桥、UIC联合推出首个中文事实核查数据集:基于证据、涵盖医疗社会等多个领域
- Download, installation and development environment construction of "harmonyos" deveco
- socket编程之常用api介绍与socket、select、poll、epoll高并发服务器模型代码实现
- [unity shader] insert pass to realize the X-ray perspective effect of model occlusion
- PIP related commands
- 【Unity Shader】插入Pass实现模型遮挡X光透视效果
- Chapter 3 business function development (safe exit)
猜你喜欢

Automated testing: a practical skill that everyone wants to know about robot framework

Debian10 compile and install MySQL

万字保姆级长文——Linkedin元数据管理平台Datahub离线安装指南

备份阿里云实例-oss-browser

CVPR 2022丨学习用于小样本语义分割的非目标知识

【C语言】字符串函数
![[paddleseg source code reading] add boundary IOU calculation in paddleseg validation (1) -- val.py file details tips](/img/f2/b6a0e5512b35cf1b695a8feecd0895.png)
[paddleseg source code reading] add boundary IOU calculation in paddleseg validation (1) -- val.py file details tips

The report of the state of world food security and nutrition was released: the number of hungry people in the world increased to 828million in 2021

Kirk Borne的本周学习资源精选【点击标题直接下载】

Backup Alibaba cloud instance OSS browser
随机推荐
Five simple ways to troubleshoot with Stace
讨论 | AR 应用落地前,要做好哪些准备?
The highest level of anonymity in C language
Static routing configuration
gsap动画库
强化学习-学习笔记8 | Q-learning
Debian10 compile and install MySQL
Test for 3 months, successful entry "byte", my interview experience summary
[trusted computing] Lesson 10: TPM password resource management (II)
Interviewer: why is the page too laggy and how to solve it? [test interview question sharing]
体总:安全有序恢复线下体育赛事,力争做到国内赛事应办尽办
Do you really understand sticky bag and half bag? 3 minutes to understand it
[C language] string function
卖空、加印、保库存,东方甄选居然一个月在抖音卖了266万单书
CVPR 2022丨学习用于小样本语义分割的非目标知识
性能测试过程和计划
[tpm2.0 principle and Application guide] Chapter 5, 7 and 8
Year SQL audit platform
Disk storage chain B-tree and b+ tree
科学家首次观察到“电子漩涡” 有助于设计出更高效的电子产品