当前位置:网站首页>Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
2022-07-07 18:39:00 【TechWeb】
7 month 7 Japan , Cisco has released a security update , Fixed Cisco Expressway Series and telepresence video communication server . Here are the details of the vulnerability :
Vulnerability Details
source :https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-overwrite-3buqW8LH
1.CVE-2022-20812 CVSS score :9.0 severity : important
Cisco Expressway Series and Cisco TelePresence VCS Cluster database for API A vulnerability in may allow an authenticated remote attacker to have administrator read and write access to the application , To carry out absolute path traversal attack on the affected devices and overwrite the file root user on the underlying operating system .
This vulnerability is due to insufficient input validation of user supplied command parameters . An attacker can exploit this vulnerability by authenticating to the system as an administrative read-write user and submitting carefully designed input to the affected command . Successful exploitation may allow an attacker to root Identity covers any file user on the underlying operating system .
2.CVE-2022-20813 CVSS score :7.4 severity : high
Cisco Expressway Series and Cisco TelePresence VCS A vulnerability in certificate validation may allow unauthenticated remote attackers unauthorized access to sensitive data .
This vulnerability is caused by incorrect certificate validation . Attackers can intercept traffic between devices by using man in the middle Technology , Then use the crafted certificate to simulate the endpoint to exploit this vulnerability . Successful exploitation may allow attackers to view the intercepted traffic or change the content of the traffic in clear text .
Affected products
The above vulnerability affects those using the default configuration Cisco Expressway Series and Cisco TelePresence VCS 14.0 Up to .
Solution
Cisco Expressway Series and Cisco TelePresence VCS To upgrade to 14.0.7 Version repairable
View more vulnerability information And upgrade, please visit the official website :
https://tools.cisco.com/security/center/publicationListing.x
边栏推荐
- Chapter 3 business function development (safe exit)
- [论文分享] Where’s Crypto?
- Chapter 2 build CRM project development environment (database design)
- 讨论 | AR 应用落地前,要做好哪些准备?
- 标准ACL与扩展ACL
- 简单几步教你如何看k线图图解
- Chapter 3 business function development (user access project)
- [trusted computing] Lesson 12: TPM authorization and conversation
- 嵌入式C语言程序调试和宏使用的技巧
- 数学分析_笔记_第11章:Fourier级数
猜你喜欢

单臂路由和三层交换的简单配置

通过 Play Integrity API 的 nonce 字段提高应用安全性

上市十天就下线过万台,欧尚Z6产品实力备受点赞

Datasimba launched wechat applet, and datanuza accepted the test of the whole scene| StartDT Hackathon

Automated testing: a practical skill that everyone wants to know about robot framework

Skills of embedded C language program debugging and macro use

Do you really understand sticky bag and half bag? 3 minutes to understand it

线程池和单例模式以及文件操作

Win11C盘满了怎么清理?Win11清理C盘的方法

Backup Alibaba cloud instance OSS browser
随机推荐
[paddleseg source code reading] add boundary IOU calculation in paddleseg validation (1) -- val.py file details tips
2022年理财有哪些产品?哪些适合新手?
[C language] string function
go语言的字符串类型、常量类型和容器类型
现货白银分析中的一些要点
Kirk Borne的本周学习资源精选【点击标题直接下载】
Is it safe to open an online futures account now? How many regular futures companies are there in China?
The report of the state of world food security and nutrition was released: the number of hungry people in the world increased to 828million in 2021
标准ACL与扩展ACL
备份阿里云实例-oss-browser
Disk storage chain B-tree and b+ tree
国内的软件测试会受到偏见吗
More than 10000 units were offline within ten days of listing, and the strength of Auchan Z6 products was highly praised
行业案例|数字化经营底座助力寿险行业转型
Win11C盘满了怎么清理?Win11清理C盘的方法
【C语言】字符串函数
回归测试的分类
sqlite sql 异常 near “with“: syntax error
[trusted computing] Lesson 13: TPM extended authorization and key management
Wireshark分析抓包数据*.cap