当前位置:网站首页>Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
Cloud security daily 220707: Cisco Expressway series and telepresence video communication server have found remote attack vulnerabilities and need to be upgraded as soon as possible
2022-07-07 18:39:00 【TechWeb】
7 month 7 Japan , Cisco has released a security update , Fixed Cisco Expressway Series and telepresence video communication server . Here are the details of the vulnerability :
Vulnerability Details
source :https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-overwrite-3buqW8LH
1.CVE-2022-20812 CVSS score :9.0 severity : important
Cisco Expressway Series and Cisco TelePresence VCS Cluster database for API A vulnerability in may allow an authenticated remote attacker to have administrator read and write access to the application , To carry out absolute path traversal attack on the affected devices and overwrite the file root user on the underlying operating system .
This vulnerability is due to insufficient input validation of user supplied command parameters . An attacker can exploit this vulnerability by authenticating to the system as an administrative read-write user and submitting carefully designed input to the affected command . Successful exploitation may allow an attacker to root Identity covers any file user on the underlying operating system .
2.CVE-2022-20813 CVSS score :7.4 severity : high
Cisco Expressway Series and Cisco TelePresence VCS A vulnerability in certificate validation may allow unauthenticated remote attackers unauthorized access to sensitive data .
This vulnerability is caused by incorrect certificate validation . Attackers can intercept traffic between devices by using man in the middle Technology , Then use the crafted certificate to simulate the endpoint to exploit this vulnerability . Successful exploitation may allow attackers to view the intercepted traffic or change the content of the traffic in clear text .
Affected products
The above vulnerability affects those using the default configuration Cisco Expressway Series and Cisco TelePresence VCS 14.0 Up to .
Solution
Cisco Expressway Series and Cisco TelePresence VCS To upgrade to 14.0.7 Version repairable
View more vulnerability information And upgrade, please visit the official website :
https://tools.cisco.com/security/center/publicationListing.x
边栏推荐
- Tips of the week 136: unordered containers
- 2022年理财有哪些产品?哪些适合新手?
- 云景网络科技面试题【杭州多测师】【杭州多测师_王sir】
- Five simple ways to troubleshoot with Stace
- 4种常见的缓存模式,你都知道吗?
- Datasimba launched wechat applet, and datanuza accepted the test of the whole scene| StartDT Hackathon
- pip相关命令
- Hash, bitmap and bloom filter for mass data De duplication
- 保证接口数据安全的10种方案
- 现货白银分析中的一些要点
猜你喜欢

Skills of embedded C language program debugging and macro use

Idea completely uninstalls installation and configuration notes

讨论 | AR 应用落地前,要做好哪些准备?

【蓝桥杯集训100题】scratch从小到大排序 蓝桥杯scratch比赛专项预测编程题 集训模拟练习题第17题

Summary of evaluation indicators and important knowledge points of regression problems

socket编程之常用api介绍与socket、select、poll、epoll高并发服务器模型代码实现

将模型的记忆保存下来!Meta&UC Berkeley提出MeMViT,建模时间支持比现有模型长30倍,计算量仅增加4.5%...
![[tpm2.0 principle and Application guide] Chapter 5, 7 and 8](/img/38/93fd986916193803bbd90805f832fa.png)
[tpm2.0 principle and Application guide] Chapter 5, 7 and 8

Performance test process and plan

Test for 3 months, successful entry "byte", my interview experience summary
随机推荐
Disk storage chain B-tree and b+ tree
Static routing configuration
[论文分享] Where’s Crypto?
Chapter 3 business function development (safe exit)
Debian10 compile and install MySQL
SQLite SQL exception near "with": syntax error
直播预约通道开启!解锁音视频应用快速上线的秘诀
高考填志愿规则
保证接口数据安全的10种方案
RIP和OSPF的区别和配置命令
[trusted computing] Lesson 11: TPM password resource management (III) NV index and PCR
回归问题的评价指标和重要知识点总结
How to clean when win11 C disk is full? Win11 method of cleaning C disk
Tips for short-term operation of spot silver that cannot be ignored
Hutool - 轻量级 DB 操作解决方案
Wireshark analyzes packet capture data * cap
Chapter 2 building CRM project development environment (building development environment)
Tips for this week 134: make_ Unique and private constructors
[trusted computing] Lesson 12: TPM authorization and conversation
More than 10000 units were offline within ten days of listing, and the strength of Auchan Z6 products was highly praised