Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerability
Vulnerability Description
A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending arbitrary HTTP requests to internal services. An exploit could allow the attacker to bypass any firewall or other protections to access unauthorized internal services. DNAC versions prior to 1.2.5 are affected.
CVSS Information
N/A
Vulnerability Type
未有动机的代理或中间人(混淆代理)
Vulnerability Title
Cisco Digital Network Architecture Center 输入验证错误漏洞
Vulnerability Description
Cisco Digital Network Architecture Center(DNA Center)是美国思科(Cisco)公司的一套数字网络体系结构解决方案。该方案能够扩展并保护网络内的设备、应用程序等。 Cisco DNA Center中的Software Image管理功能存在安全漏洞,该漏洞源于程序没有充分地验证用户提交的输入。远程攻击者可通过发送任意HTTP请求利用该漏洞绕过任意防火墙或其他保护机制,访问内部服务。
CVSS Information
N/A
Vulnerability Type
N/A