当前位置:网站首页>Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
2022-07-07 18:39:00 【TechWeb】
7 month 7 Japan , Cisco has released a security update , Fixed Cisco Expressway Series and telepresence video communication server . Here are the details of the vulnerability :
Vulnerability Details
source :https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-overwrite-3buqW8LH
1.CVE-2022-20812 CVSS score :9.0 severity : important
Cisco Expressway Series and Cisco TelePresence VCS Cluster database for API A vulnerability in may allow an authenticated remote attacker to have administrator read and write access to the application , To carry out absolute path traversal attack on the affected devices and overwrite the file root user on the underlying operating system .
This vulnerability is due to insufficient input validation of user supplied command parameters . An attacker can exploit this vulnerability by authenticating to the system as an administrative read-write user and submitting carefully designed input to the affected command . Successful exploitation may allow an attacker to root Identity covers any file user on the underlying operating system .
2.CVE-2022-20813 CVSS score :7.4 severity : high
Cisco Expressway Series and Cisco TelePresence VCS A vulnerability in certificate validation may allow unauthenticated remote attackers unauthorized access to sensitive data .
This vulnerability is caused by incorrect certificate validation . Attackers can intercept traffic between devices by using man in the middle Technology , Then use the crafted certificate to simulate the endpoint to exploit this vulnerability . Successful exploitation may allow attackers to view the intercepted traffic or change the content of the traffic in clear text .
Affected products
The above vulnerability affects those using the default configuration Cisco Expressway Series and Cisco TelePresence VCS 14.0 Up to .
Solution
Cisco Expressway Series and Cisco TelePresence VCS To upgrade to 14.0.7 Version repairable
View more vulnerability information And upgrade, please visit the official website :
https://tools.cisco.com/security/center/publicationListing.x
边栏推荐
- Five simple ways to troubleshoot with Stace
- Yunjing network technology interview question [Hangzhou multi tester] [Hangzhou multi tester _ Wang Sir]
- Datasimba launched wechat applet, and datanuza accepted the test of the whole scene| StartDT Hackathon
- [principles and technologies of network attack and Defense] Chapter 5: denial of service attack
- [tpm2.0 principle and Application guide] Chapter 5, 7 and 8
- ICer知识点杂烩(后附大量题目,持续更新中)
- How to clean when win11 C disk is full? Win11 method of cleaning C disk
- 强化学习-学习笔记8 | Q-learning
- AI defeated mankind and designed a better economic mechanism
- Win11C盘满了怎么清理?Win11清理C盘的方法
猜你喜欢
Kirk borne's selection of learning resources this week [click the title to download directly]
CVPR 2022丨学习用于小样本语义分割的非目标知识
[trusted computing] Lesson 13: TPM extended authorization and key management
Automated testing: a practical skill that everyone wants to know about robot framework
【C语言】字符串函数
你真的理解粘包与半包吗?3分钟搞懂它
Nunjuks template engine
[PaddleSeg源码阅读] PaddleSeg Validation 中添加 Boundary IoU的计算(1)——val.py文件细节提示
RIP和OSPF的区别和配置命令
行业案例|数字化经营底座助力寿险行业转型
随机推荐
[principle and technology of network attack and Defense] Chapter 1: Introduction
海量数据去重的hash,bitmap与布隆过滤器Bloom Filter
嵌入式C语言程序调试和宏使用的技巧
ICer知识点杂烩(后附大量题目,持续更新中)
强化学习-学习笔记8 | Q-learning
Wireshark分析抓包数据*.cap
数学分析_笔记_第11章:Fourier级数
Performance test process and plan
Tips of this week 135: test the contract instead of implementation
Tips for this week 140: constants: safety idioms
五种网络IO模型
Backup Alibaba cloud instance OSS browser
Some key points in the analysis of spot Silver
卖空、加印、保库存,东方甄选居然一个月在抖音卖了266万单书
【剑指 Offer】59 - I. 滑动窗口的最大值
[network attack and defense principle and technology] Chapter 4: network scanning technology
[trusted computing] Lesson 10: TPM password resource management (II)
静态路由配置
Chapter 2 build CRM project development environment (database design)
[trusted computing] Lesson 11: TPM password resource management (III) NV index and PCR