Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an Authentication Request Processing Arbitrary Command Execution Vulnerability. More Information: CSCvc76642. Known Affected Releases: 2.2(9.76).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cisco Elastic Services Controller 安全漏洞
Vulnerability Description
Cisco Elastic Services Controller(ESC)是美国思科(Cisco)公司的一个开源的模块化系统。 Cisco Elastic Services Controller中的esc_listener.py脚本中存在任意代码执行漏洞,该漏洞源于程序没有充分的过滤参数。攻击者可通过TPC 6000端口向监控的守护进程发送特制的请求利用该漏洞以tomcat用户身份执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A