Cisco Adaptive Security Appliances Software(ASA Software)是美国思科(Cisco)公司的一套防火墙和网络安全平台。该平台提供了对数据和网络资源的高度安全的访问等功能。 Cisco ASA中的smart tunnel功能存在输入验证错误漏洞,该漏洞源于ASA smart tunnel在客户端设备上创建的本地系统文件分配了较宽松的权限。本地攻击者可通过运行恶意的脚本利用该漏洞在用户未知情的情况下将权限提升至root。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | unspecified ~ 9.8.4.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-1945 | Cisco Adaptive Security Appliance Smart Tunnel Vulnerabilities | |
| CVE-2019-1928 | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne | |
| CVE-2019-1929 | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne | |
| CVE-2019-1934 | Cisco Adaptive Security Appliance Software Web-Based Management Interface Privilege Escala | |
| CVE-2019-1926 | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne | |
| CVE-2019-1927 | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne | |
| CVE-2019-1918 | Cisco IOS XR Software Intermediate System–to–Intermediate System Denial of Service Vulnera | |
| CVE-2019-1924 | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne | |
| CVE-2019-1925 | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne | |
| CVE-2019-1910 | Cisco IOS XR Software Intermediate System to Intermediate System Denial of Service Vulnera | |
| CVE-2019-1895 | Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability | |
| CVE-2019-1913 | Cisco Small Business 220 Series Smart Switches Remote Code Execution Vulnerabilities | |
| CVE-2019-1914 | Cisco Small Business 220 Series Smart Switches Command Injection Vulnerability | |
| CVE-2019-1912 | Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerability |
No comments yet