当前位置:网站首页>Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
2022-07-07 18:39:00 【TechWeb】
7 month 7 Japan , Cisco has released a security update , Fixed Cisco Expressway Series and telepresence video communication server . Here are the details of the vulnerability :
Vulnerability Details
source :https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-overwrite-3buqW8LH
1.CVE-2022-20812 CVSS score :9.0 severity : important
Cisco Expressway Series and Cisco TelePresence VCS Cluster database for API A vulnerability in may allow an authenticated remote attacker to have administrator read and write access to the application , To carry out absolute path traversal attack on the affected devices and overwrite the file root user on the underlying operating system .
This vulnerability is due to insufficient input validation of user supplied command parameters . An attacker can exploit this vulnerability by authenticating to the system as an administrative read-write user and submitting carefully designed input to the affected command . Successful exploitation may allow an attacker to root Identity covers any file user on the underlying operating system .
2.CVE-2022-20813 CVSS score :7.4 severity : high
Cisco Expressway Series and Cisco TelePresence VCS A vulnerability in certificate validation may allow unauthenticated remote attackers unauthorized access to sensitive data .
This vulnerability is caused by incorrect certificate validation . Attackers can intercept traffic between devices by using man in the middle Technology , Then use the crafted certificate to simulate the endpoint to exploit this vulnerability . Successful exploitation may allow attackers to view the intercepted traffic or change the content of the traffic in clear text .
Affected products
The above vulnerability affects those using the default configuration Cisco Expressway Series and Cisco TelePresence VCS 14.0 Up to .
Solution
Cisco Expressway Series and Cisco TelePresence VCS To upgrade to 14.0.7 Version repairable
View more vulnerability information And upgrade, please visit the official website :
https://tools.cisco.com/security/center/publicationListing.x
边栏推荐
- 五种网络IO模型
- Tips for this week 140: constants: safety idioms
- [trusted computing] Lesson 13: TPM extended authorization and key management
- 清华、剑桥、UIC联合推出首个中文事实核查数据集:基于证据、涵盖医疗社会等多个领域
- Summary of debian10 system problems
- 线程池中的线程工厂
- 能同时做三个分割任务的模型,性能和效率优于MaskFormer!Meta&UIUC提出通用分割模型,性能优于任务特定模型!开源!...
- PHP面试题 foreach($arr as &$value)与foreach($arr as $value)的用法
- What skills can you master to be a "master tester" when doing software testing?
- 上市十天就下线过万台,欧尚Z6产品实力备受点赞
猜你喜欢
Nunjuks template engine
Summary of debian10 system problems
Classification of regression tests
Tips of the week 136: unordered containers
Industry case | digital operation base helps the transformation of life insurance industry
单臂路由和三层交换的简单配置
AntiSamy:防 XSS 攻击的一种解决方案使用教程
Kirk borne's selection of learning resources this week [click the title to download directly]
简单几步教你如何看k线图图解
AI defeated mankind and designed a better economic mechanism
随机推荐
低代码助力企业数字化转型会让程序员失业?
NAT地址转换
强化学习-学习笔记8 | Q-learning
回归测试的分类
[principle and technology of network attack and Defense] Chapter 6: Trojan horse
Personal best practice demo sharing of enum + validation
[network attack and defense principle and technology] Chapter 4: network scanning technology
标准ACL与扩展ACL
清华、剑桥、UIC联合推出首个中文事实核查数据集:基于证据、涵盖医疗社会等多个领域
海量数据去重的hash,bitmap与布隆过滤器Bloom Filter
socket編程之常用api介紹與socket、select、poll、epoll高並發服務器模型代碼實現
五种网络IO模型
Kirk Borne的本周学习资源精选【点击标题直接下载】
直播预约通道开启!解锁音视频应用快速上线的秘诀
SD_DATA_SEND_SHIFT_REGISTER
[trusted computing] Lesson 13: TPM extended authorization and key management
磁盘存储链式的B树与B+树
AntiSamy:防 XSS 攻击的一种解决方案使用教程
小试牛刀之NunJucks模板引擎
Classification of regression tests