Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmware_action.jsp, and (3) file.jsp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cisco Clean Access多个JSP页面访问验证漏洞
Vulnerability Description
Cisco Clean Access(CCA)是可以自动检测、隔离和清除试图访问网络的感染或有漏洞设备的软件解决方案。 Cisco Clean Access(CCA)的访问认证存在漏洞,远程攻击者可能非授权访问服务器。CCA对/admin/uploadclient.jsp缺少认证检查,这样任何浏览页面的用户都可以直接向/installer/windows文件夹上传文件,导致拒绝服务或其他非授权访问。apply_firmware_action.jsp和file.jsp中也存在类似的问题。
CVSS Information
N/A
Vulnerability Type
N/A