Cisco StarOS是美国思科(Cisco)公司的一套虚拟化操作系统。 Cisco StarOS存在命令注入漏洞,该漏洞允许经过身份验证的本地攻击者可利用该漏洞在受影响的设备上提升特权。此漏洞是由于CLI命令的输入验证不足造成的。攻击者可利用该漏洞可以通过向CLI发送精心设计的命令来利用这个漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco ASR 5000 Series Software | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-20755 | 9.0 CRITICAL | Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities |
| CVE-2022-20754 | 9.0 CRITICAL | Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities |
| CVE-2022-20756 | 8.6 HIGH | Cisco Identity Services Engine RADIUS Service Denial of Service Vulnerability |
| CVE-2022-20762 | 7.8 HIGH | Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure Privilege Escalation Vuln |
| CVE-2022-20774 | 6.8 MEDIUM | Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Cross-Site Request |
| CVE-2022-20782 | 6.5 MEDIUM | Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability |
| CVE-2022-20784 | 5.8 MEDIUM | Cisco Web Security Appliance Filter Bypass Vulnerability |
| CVE-2022-20741 | 5.4 MEDIUM | Cisco Secure Network Analytics Network Diagrams Application Cross-Site Scripting Vulnerabi |
| CVE-2022-20763 | 5.4 MEDIUM | Cisco Webex Meetings Java Deserialization Vulnerability |
| CVE-2022-20781 | 5.4 MEDIUM | Cisco Web Security Appliance Stored Cross-Site Scripting Vulnerability |
| CVE-2022-20675 | 5.3 MEDIUM | Multiple Cisco Security Products Simple Network Management Protocol Service Denial of Serv |
No comments yet