Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco IOS XE Software Web UI Authorization Bypass Vulnerability
Vulnerability Description
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize parts of the web UI for which they are not authorized.The vulnerability is due to insufficient authorization of web UI access requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web UI. A successful exploit could allow the attacker to utilize parts of the web UI for which they are not authorized. This could allow a Read-Only user to perform actions of an Admin user.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
Cisco IOS和IOS XE 安全漏洞
Vulnerability Description
Cisco IOS和IOS XE都是美国思科(Cisco)公司的一套为其网络设备开发的操作系统。 Cisco IOS XE Web UI存在安全漏洞,该漏洞源于Web UI访问请求的授权不足所致,攻击者可利用该漏洞通过向Web UI发送精心设计的HTTP请求。
CVSS Information
N/A
Vulnerability Type
N/A