漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cisco Enterprise NFV Infrastructure Software Information Disclosure Vulnerability
Vulnerability Description
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation checks. An attacker could exploit this vulnerability by sending a malicious API request with the authentication credentials of a low-privileged user. A successful exploit could allow the attacker to read any file on the affected system.
CVSS Information
N/A
Vulnerability Type
授权机制不恰当
Vulnerability Title
Cisco Enterprise NFV Infrastructure Software 信息泄露漏洞
Vulnerability Description
Cisco Enterprise NFV Infrastructure Software(NFVIS)是美国思科(Cisco)公司的一套NVF基础架构软件平台。该平台可以通过中央协调器和控制器实现虚拟化服务的全生命周期管理。 Cisco Enterprise NFVIS中的REST API存在信息泄露漏洞,该漏洞源于程序没有充分执行授权和参数检测。远程攻击者可通过发送带有低权限用户身份验证凭证的恶意API请求利用该漏洞读取受影响系统上的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A