Cisco Policy Suite (CPS) Software是美国思科(Cisco)公司的一套下一代策略管理软件。该软件提供了基于用户的业务规则、应用程序和网络资源的实时管理等功能。shell user accounts是其中的一个账户管理组件。 CPS Software中的shell用户账户管理存在提权漏洞,该漏洞源于程序对shell用户账户实施了基于角色的错误的访问控制(RBAC)。本地攻击者可通过认证受影响的设备并提供特制的用户输入利用该漏洞在受影响的系统上获取提升的权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco Systems, Inc. | Policy Suite | 9.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-6777 | Cisco Elastic Services Controller ConfD服务器信息泄露漏洞 | |
| CVE-2017-6790 | Cisco TelePresence Video Communication Server 安全漏洞 | |
| CVE-2017-6788 | Cisco AnyConnect Secure Mobility Client Software 跨站脚本漏洞 | |
| CVE-2017-6786 | Cisco Elastic Services Controller 信息泄露漏洞 | |
| CVE-2017-6785 | Cisco Unified Communications Manager 权限许可和访问控制漏洞 | |
| CVE-2017-6784 | Cisco RV340、RV345和RV345P Dual WAN Gigabit VPN Routers 信息泄露漏洞 | |
| CVE-2017-6783 | 多款Cisco产品SNMP polling 信息泄露漏洞 | |
| CVE-2017-6782 | Cisco Prime Infrastructure 安全漏洞 | |
| CVE-2017-6778 | Cisco Ultra Services Platform Elastic Services Controller Web界面信息泄露漏洞 | |
| CVE-2017-6710 | Cisco Virtual Network Function Element Manager 安全漏洞 | |
| CVE-2017-6776 | Cisco Elastic Services Controller 跨站脚本漏洞 | |
| CVE-2017-6775 | Cisco ASR 5000 Series Aggregated Services Routers StarOS 权限许可和访问控制问题漏洞 | |
| CVE-2017-6774 | Cisco ASR 5000 Series Aggregated Services Routers StarOS 安全漏洞 | |
| CVE-2017-6773 | Cisco ASR 5000 Series Aggregated Services Routers StarOS 安全漏洞 | |
| CVE-2017-6772 | Cisco Elastic Services Controller 信息泄露漏洞 | |
| CVE-2017-6771 | Cisco Ultra Services Framework AutoVNF automation工具信息泄露漏洞 | |
| CVE-2017-6768 | Cisco Application Policy Infrastructure Controller 权限许可和访问控制问题漏洞 | |
| CVE-2017-6767 | Cisco Application Policy Infrastructure Controller 权限许可和访问控制问题漏洞 |
No comments yet