当前位置:网站首页>Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
2022-07-07 18:39:00 【TechWeb】
7 month 7 Japan , Cisco has released a security update , Fixed Cisco Expressway Series and telepresence video communication server . Here are the details of the vulnerability :
Vulnerability Details
source :https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-overwrite-3buqW8LH
1.CVE-2022-20812 CVSS score :9.0 severity : important
Cisco Expressway Series and Cisco TelePresence VCS Cluster database for API A vulnerability in may allow an authenticated remote attacker to have administrator read and write access to the application , To carry out absolute path traversal attack on the affected devices and overwrite the file root user on the underlying operating system .
This vulnerability is due to insufficient input validation of user supplied command parameters . An attacker can exploit this vulnerability by authenticating to the system as an administrative read-write user and submitting carefully designed input to the affected command . Successful exploitation may allow an attacker to root Identity covers any file user on the underlying operating system .
2.CVE-2022-20813 CVSS score :7.4 severity : high
Cisco Expressway Series and Cisco TelePresence VCS A vulnerability in certificate validation may allow unauthenticated remote attackers unauthorized access to sensitive data .
This vulnerability is caused by incorrect certificate validation . Attackers can intercept traffic between devices by using man in the middle Technology , Then use the crafted certificate to simulate the endpoint to exploit this vulnerability . Successful exploitation may allow attackers to view the intercepted traffic or change the content of the traffic in clear text .
Affected products
The above vulnerability affects those using the default configuration Cisco Expressway Series and Cisco TelePresence VCS 14.0 Up to .
Solution
Cisco Expressway Series and Cisco TelePresence VCS To upgrade to 14.0.7 Version repairable
View more vulnerability information And upgrade, please visit the official website :
https://tools.cisco.com/security/center/publicationListing.x
边栏推荐
- PHP面试题 foreach($arr as &$value)与foreach($arr as $value)的用法
- 嵌入式C语言程序调试和宏使用的技巧
- [principle and technology of network attack and Defense] Chapter 7: password attack technology Chapter 8: network monitoring technology
- [PaddleSeg源码阅读] PaddleSeg Validation 中添加 Boundary IoU的计算(1)——val.py文件细节提示
- 【蓝桥杯集训100题】scratch从小到大排序 蓝桥杯scratch比赛专项预测编程题 集训模拟练习题第17题
- 国内的软件测试会受到偏见吗
- Discuss | frankly, why is it difficult to implement industrial AR applications?
- Static routing configuration
- [demo] circular queue and conditional lock realize the communication between goroutines
- 直播预约通道开启!解锁音视频应用快速上线的秘诀
猜你喜欢
AI 击败了人类,设计了更好的经济机制
Learn to make dynamic line chart in 3 minutes!
debian10编译安装mysql
Skills of embedded C language program debugging and macro use
AI defeated mankind and designed a better economic mechanism
【C语言】字符串函数
[principles and technologies of network attack and Defense] Chapter 5: denial of service attack
[principle and technology of network attack and Defense] Chapter 1: Introduction
科学家首次观察到“电子漩涡” 有助于设计出更高效的电子产品
NAT地址转换
随机推荐
C语言中匿名的最高境界
【Unity Shader】插入Pass实现模型遮挡X光透视效果
gsap动画库
golang 客户端服务端登录
go语言的字符串类型、常量类型和容器类型
How to clean when win11 C disk is full? Win11 method of cleaning C disk
Summary of evaluation indicators and important knowledge points of regression problems
Personal best practice demo sharing of enum + validation
财富证券证券怎么开户?通过链接办理股票开户安全吗
国内的软件测试会受到偏见吗
Classification of regression tests
What is the general yield of financial products in 2022?
What skills can you master to be a "master tester" when doing software testing?
String type, constant type and container type of go language
NAT地址转换
云安全日报220707:思科Expressway系列和网真视频通信服务器发现远程攻击漏洞,需要尽快升级
单臂路由和三层交换的简单配置
科学家首次观察到“电子漩涡” 有助于设计出更高效的电子产品
[论文分享] Where’s Crypto?
[demo] circular queue and conditional lock realize the communication between goroutines