目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2019-1919— Cisco FindIT Network Management Software 信任管理问题漏洞

AI Predicted 6.5 Difficulty: Moderate EPSS 0.32% · P25
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2019-1919の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Cisco FindIT Network Management Software Static Credentials Vulnerability
ソース: CVE Program / CVE List V5
脆弱性説明
A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the presence of an account with static credentials in the underlying Linux operating system. An attacker could exploit this vulnerability by logging in to the command line of the affected VM with the static account. A successful exploit could allow the attacker to log in with root-level privileges. This vulnerability affects only Cisco FindIT Network Manager and Cisco FindIT Network Probe Release 1.1.4 if these products are using Cisco-supplied VM images. No other releases or deployment models are known to be vulnerable.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
使用硬编码的凭证
ソース: CVE Program / CVE List V5
脆弱性タイトル
Cisco FindIT Network Management Software 信任管理问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Cisco FindIT Network Management Software中的virtual machine (VM) images存在信任管理问题漏洞,该漏洞源于底层Linux操作系统中账户使用了静态凭证。本地攻击者可利用该漏洞以root权限登录设备。以下产品及版本受到影响:Cisco FindIT Network Manager 1.1.4版本;Cisco FindIT Network Probe 1.1.4版本。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
CiscoCisco FindIT Network Manager unspecified ~ 2.0 -

II. CVE-2019-1919の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2019-1919のインテリジェンス情報

登录查看更多情报信息。

CVE-2019-1919 厂商安全公告 (2)

Same Patch Batch · Cisco · 2019-07-17 · 8 CVEs total

CVE-2019-1917Cisco Vision Dynamic Signage Director REST API Authentication Bypass Vulnerability
CVE-2019-1920Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
CVE-2019-1942Cisco Identity Services Engine Blind SQL Injection Vulnerability
CVE-2019-1941Cisco Identity Services Engine Cross-Site Scripting Vulnerability
CVE-2019-1940Cisco Industrial Network Director Web Services Management Agent Unauthorized Information D
CVE-2019-1923Cisco Small Business SPA500 Series IP Phones Local Command Execution Vulnerability
CVE-2019-1943Cisco Small Business Series Switches Open Redirect Vulnerability

IV. 関連脆弱性

V. CVE-2019-1919へのコメント

まだコメントはありません


コメントを残す