Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco Integrated Management Controller CSR Generation Command Injection Vulnerability
Vulnerability Description
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based management interface. An attacker could exploit this vulnerability by submitting a crafted CSR in the web-based management interface. A successful exploit could allow an attacker with administrator privileges to execute arbitrary commands on the device with full root privileges.
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Cisco Integrated Management Controller 操作系统命令注入漏洞
Vulnerability Description
Cisco Integrated Management Controller(IMC)是美国思科(Cisco)公司的一套用于对UCS(统一计算系统)进行管理的软件。该软件支持HTTP、SSH访问等,并可对服务器进行开机、关机和重启等操作。 Cisco IMC中基于Web的管理界面存在操作系统命令注入漏洞,该漏洞源于该界面没有充分验证用户提交的输入。远程攻击者可通过提交特制的证书签名请求利用该漏洞注入任意命令并获取root权限。以下产品及版本受到影响:Cisco UCS C-Series Servers(处
CVSS Information
N/A
Vulnerability Type
N/A