Cisco ConfD是美国思科(Cisco)公司的一个管理软件。 Cisco ConfD存在安全漏洞,该漏洞源于受影响的软件以特权用户启用CLI的ConfD内置SSH服务器时运行的情况下错误地运行SFTP用户服务。该漏洞允许经过身份验证的本地攻击者在远行ConfD的账户中执行任意命令,并且可以通过对受影响的设备进行身份验证并在SFTP接口发送一系列命令将账户权限提升到特权用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco ConfD | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-1610 | 9.8 CRITICAL | Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Web Management Vulnera |
| CVE-2021-1609 | 9.8 CRITICAL | Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Web Management Vulnera |
| CVE-2021-1602 | 8.2 HIGH | Cisco Small Business RV160 and RV260 Series VPN Routers Remote Command Execution Vulnerabi |
| CVE-2021-1593 | 7.3 HIGH | Cisco Packet Tracer for Windows DLL Injection Vulnerability |
| CVE-2021-34707 | 6.5 MEDIUM | Cisco Evolved Programmable Network Manager Sensitive Information Disclosure Vulnerability |
| CVE-2021-1522 | 4.3 MEDIUM | Cisco Connected Mobile Experiences Strong Authentication Requirements Enforcement Bypass |
No comments yet