漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files or execute malicious code on an affected system. The vulnerability is due to the absence of validation checks for the input that is used to create symbolic links. This vulnerability affects all releases of the Cisco Ultra Services Framework prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvc76654.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Cisco Ultra Services Framework 信息泄露漏洞
Vulnerability Description
Cisco Ultra Services Framework是美国思科(Cisco)公司的一个智能在线服务交付平台。 Cisco Ultra Services Framework 5.0.3之前的版本和5.1之前的版本中的AutoVNF工具的symbolic link (symlink)创建功能存在信息泄露漏洞,该漏洞源于程序没有充分的验证用于创建符号链接的输入。远程攻击者可利用该漏洞读取敏感信息或在系统上执行恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A