漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
Cisco IOS XE Software Web UI Cross-Site WebSocket Hijacking Vulnerability
漏洞信息
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient HTTP protections in the web UI on an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the web UI to follow a crafted link. A successful exploit could allow the attacker to corrupt memory on the affected device, forcing it to reload and causing a DoS condition.
漏洞信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
漏洞
对数据真实性的验证不充分
漏洞
Cisco IOS XE 数据伪造问题漏洞
漏洞信息
Cisco IOS XE Software是美国思科(Cisco)公司的一个操作系统。用于企业有线和无线访问,汇聚,核心和WAN的单一操作系统,Cisco IOS XE降低了业务和网络的复杂性。 Cisco IOS XE Software 存在数据伪造问题漏洞,该漏洞源于web界面HTTP保护不足。攻击者可利用该漏洞实施跨站点WebSocket劫持(CSWSH)攻击,并在受影响的设备上导致拒绝服务。
漏洞信息
N/A
漏洞
N/A