Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco SD-WAN vManage Software Cypher Query Language Injection Vulnerability
Vulnerability Description
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the interface of an affected system. A successful exploit could allow the attacker to obtain sensitive information.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
数据查询逻辑中特殊元素的不当中和
Vulnerability Title
Cisco SD-WAN vManage Software 安全漏洞
Vulnerability Description
Cisco SD-WAN vManage Software是美国思科(Cisco)公司的一款用于SD-WAN(软件定义广域网络)解决方案的管理软件。 Cisco SD-WAN vManage Software 存在安全漏洞,该漏洞源于web管理界面的输入验证不足造成的。该漏洞可能允许经过身份认证的远程攻击者对受影响的系统进行密码查询语言注入攻击。攻击者可以通过向受影响系统的接口发送精心设计的HTTP请求来利用这个漏洞。成功的攻击可以让攻击者可利用该漏洞获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A