Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco IOS XR Software Arbitrary File Read and Write Vulnerability
Vulnerability Description
A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vulnerability is due to insufficient input validation of arguments that are supplied by the user for a specific file transfer method. An attacker with lower-level privileges could exploit this vulnerability by specifying Secure Copy Protocol (SCP) parameters when authenticating to a device. A successful exploit could allow the attacker to elevate their privileges and retrieve and upload files on a device that they should not have access to.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
参数注入或修改
Vulnerability Title
Cisco IOS XR 参数注入漏洞
Vulnerability Description
Cisco IOS XR是美国思科(Cisco)公司的一套为其网络设备开发的操作系统。 Cisco IOS XR软件存在参数注入漏洞,该漏洞源于Cisco IOS XR Software的SSH Server进程对于用户为特定文件传输方法提供的参数的输入验证不足。这可能允许经过身份验证的远程攻击者可利用该漏洞覆盖并读取本地设备上的任意文件。具有低级权限的攻击者可利用该漏洞可以通过在对设备进行身份验证时指定安全复制协议(SCP)参数来利用该漏洞。成功的攻击可以让攻击者可利用该漏洞提升他们的权限,并在他们应该
CVSS Information
N/A
Vulnerability Type
N/A