当前位置:网站首页>Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
2022-07-07 18:39:00 【TechWeb】
7 month 7 Japan , Cisco has released a security update , Fixed Cisco Expressway Series and telepresence video communication server . Here are the details of the vulnerability :
Vulnerability Details
source :https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-overwrite-3buqW8LH
1.CVE-2022-20812 CVSS score :9.0 severity : important
Cisco Expressway Series and Cisco TelePresence VCS Cluster database for API A vulnerability in may allow an authenticated remote attacker to have administrator read and write access to the application , To carry out absolute path traversal attack on the affected devices and overwrite the file root user on the underlying operating system .
This vulnerability is due to insufficient input validation of user supplied command parameters . An attacker can exploit this vulnerability by authenticating to the system as an administrative read-write user and submitting carefully designed input to the affected command . Successful exploitation may allow an attacker to root Identity covers any file user on the underlying operating system .
2.CVE-2022-20813 CVSS score :7.4 severity : high
Cisco Expressway Series and Cisco TelePresence VCS A vulnerability in certificate validation may allow unauthenticated remote attackers unauthorized access to sensitive data .
This vulnerability is caused by incorrect certificate validation . Attackers can intercept traffic between devices by using man in the middle Technology , Then use the crafted certificate to simulate the endpoint to exploit this vulnerability . Successful exploitation may allow attackers to view the intercepted traffic or change the content of the traffic in clear text .
Affected products
The above vulnerability affects those using the default configuration Cisco Expressway Series and Cisco TelePresence VCS 14.0 Up to .
Solution
Cisco Expressway Series and Cisco TelePresence VCS To upgrade to 14.0.7 Version repairable
View more vulnerability information And upgrade, please visit the official website :
https://tools.cisco.com/security/center/publicationListing.x
边栏推荐
- pip相关命令
- SQLite SQL exception near "with": syntax error
- A few simple steps to teach you how to see the K-line diagram
- 五种网络IO模型
- Introduction of common API for socket programming and code implementation of socket, select, poll, epoll high concurrency server model
- 开发一个小程序商城需要多少钱?
- 上市十天就下线过万台,欧尚Z6产品实力备受点赞
- [4500 word summary] a complete set of skills that a software testing engineer needs to master
- [trusted computing] Lesson 11: TPM password resource management (III) NV index and PCR
- 云景网络科技面试题【杭州多测师】【杭州多测师_王sir】
猜你喜欢
The report of the state of world food security and nutrition was released: the number of hungry people in the world increased to 828million in 2021
Five network IO models
Interviewer: why is the page too laggy and how to solve it? [test interview question sharing]
debian10编译安装mysql
Chapter 3 business function development (user access project)
CVPR 2022丨学习用于小样本语义分割的非目标知识
[paddleseg source code reading] add boundary IOU calculation in paddleseg validation (1) -- val.py file details tips
卖空、加印、保库存,东方甄选居然一个月在抖音卖了266万单书
【蓝桥杯集训100题】scratch从小到大排序 蓝桥杯scratch比赛专项预测编程题 集训模拟练习题第17题
将模型的记忆保存下来!Meta&UC Berkeley提出MeMViT,建模时间支持比现有模型长30倍,计算量仅增加4.5%...
随机推荐
科学家首次观察到“电子漩涡” 有助于设计出更高效的电子产品
Tips of this week 141: pay attention to implicit conversion to bool
用存储过程、定时器、触发器来解决数据分析问题
Introduction de l'API commune de programmation de socket et mise en œuvre de socket, select, Poll et epoll
Chapter 3 business function development (user access project)
[trusted computing] Lesson 12: TPM authorization and conversation
Tips of this week 135: test the contract instead of implementation
Backup Alibaba cloud instance OSS browser
行业案例|数字化经营底座助力寿险行业转型
【Unity Shader】插入Pass实现模型遮挡X光透视效果
The highest level of anonymity in C language
直播预约通道开启!解锁音视频应用快速上线的秘诀
Tips for short-term operation of spot silver that cannot be ignored
Chapter 3 business function development (user login)
2022年理财有哪些产品?哪些适合新手?
Improve application security through nonce field of play integrity API
Tips for this week 131: special member functions and ` = Default`
[C language] string function
AI defeated mankind and designed a better economic mechanism
Industry case | digital operation base helps the transformation of life insurance industry