Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Vulnerability Description
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS Information
N/A
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
Cisco IOS XE 操作系统命令注入漏洞
Vulnerability Description
Cisco IOS XE是美国思科(Cisco)公司的一套为其网络设备开发的操作系统。 Cisco IOS XE中基于Web的用户界面存在操作系统命令注入漏洞,该漏洞源于程序没有正确处理用户提交的输入。攻击者可借助特制的输入参数利用该漏洞以提升的权限(15级)执行Cisco IOS命令。
CVSS Information
N/A
Vulnerability Type
N/A