Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco HyperFlex UI Clickjacking Vulnerability
Vulnerability Description
A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame data. A successful exploit could allow the attacker to perform a clickjacking attack where the user is tricked into clicking a malicious link.
CVSS Information
N/A
Vulnerability Type
保护机制失效
Vulnerability Title
Cisco HyperFlex Software 输入验证错误漏洞
Vulnerability Description
Cisco HyperFlex Software是美国思科(Cisco)公司的一套可扩展的分布式文件系统。该系统通过云管理提供统一的计算、存储和网络,提供企业级数据管理和优化服务。 Cisco HyperFlex Software中的Web UI存在安全漏洞,该漏洞源于程序没有充分的对HTTP请求中的iFrame数据执行输入验证。远程攻击者可通过发送含有恶意iFrame数据的HTTP数据包利用该漏洞执行点击劫持攻击。
CVSS Information
N/A
Vulnerability Type
N/A