漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
Vulnerability Description
A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on the underlying operating system. An attacker could exploit this vulnerability by sending a crafted API request to Cisco vManage as a lower-privileged user and gaining access to sensitive information that they would not normally be authorized to access.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过数据查询的敏感数据暴露
Vulnerability Title
Cisco SD-WAN vManage Software 安全漏洞
Vulnerability Description
Cisco SD-WAN vManage Software是美国思科(Cisco)公司的一款用于SD-WAN(软件定义广域网络)解决方案的管理软件。 Cisco SD-WAN vManage Software存在安全漏洞,该漏洞源于对底层操作系统的 API 授权检查不足。攻击者利用此漏洞可以通过以较低权限用户的身份向 Cisco vManage 发送精心设计的 API 请求并获得对他们通常无权访问的敏感信息的访问权限。以下产品和版本受到影响:18.3 及之前版本、18.4、19.2、20.1、20.3、2
CVSS Information
N/A
Vulnerability Type
N/A