Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco IOx Application Hosting Environment Vulnerabilities
Vulnerability Description
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Cisco Iox 竞争条件问题漏洞
Vulnerability Description
Cisco Iox是美国思科(Cisco)公司的一个结合了Cisco IOS和Linux OS用于安全网络连接以及开发IOT应用的安全开发环境。 Cisco Iox 应用托管环境存在竞争条件问题漏洞,该漏洞源于令牌分配的争用条件。攻击者可以通过不断尝试调用上传 API 来利用此漏洞,如果调用与部署应用程序的授权管理员同时发生,则攻击者可能会争用令牌并被授予绕过身份验证的能力。成功利用此漏洞可让攻击者绕过身份验证。以下产品和版本受到影响:Cisco ASR、Cisco Catalyst、IOS by Cis
CVSS Information
N/A
Vulnerability Type
N/A