Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The attacker would also have to have access to the internal VLAN where CPS is deployed. The vulnerability is due to incorrect permissions of certain system files and not sufficiently protecting sensitive data that is at rest. An attacker could exploit the vulnerability by using certain tools available on the internal network interface to request and view system files. An exploit could allow the attacker to find out sensitive information about the application. Cisco Bug IDs: CSCvf77666.
CVSS Information
N/A
Vulnerability Type
权限、特权和访问控制
Vulnerability Title
Cisco Policy Suite Policy and Charging Rules Function 信息泄露漏洞
Vulnerability Description
Cisco Policy Suite(CPS)是美国思科(Cisco)公司的一套下一代策略管理解决方案。该方案提供了基于用户的业务规则、应用程序和网络资源的实时管理等功能。Policy and Charging Rules Function(PCRF)是其中的一个策略、规则设置功能组件。 CPS中的PCRF存在信息泄露漏洞,该漏洞源于程序为系统文件分配了错误的权限,并且没有充分的保护敏感数据。远程攻击者可通过使用内部网络界面上可用的工具利用该漏洞访问敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A