Cisco Umbrella是美国思科(Cisco)公司的一套云安全平台。该平台能够预防网络钓鱼、恶意软件和勒索软件等网络威胁。 Cisco Umbrella 虚拟设备(VA)存在安全漏洞,该漏洞源于存在静态 SSH 主机密钥。攻击者利用此漏洞可以通过对与 Umbrella VA 的 SSH 连接执行中间人攻击。成功利用此漏洞可让攻击者了解管理员凭据、更改配置或重新加载 VA。以下产品和版本受到影响:3.2 及之前版本和 3.3 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Umbrella Insights Virtual Appliance | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-20732 | 7.8 HIGH | Cisco Virtualized Infrastructure Manager Privilege Escalation Vulnerability |
| CVE-2022-20783 | 7.5 HIGH | Cisco TelePresence Collaboration Endpoint and RoomOS Software H.323 Denial of Service Vuln |
| CVE-2022-20790 | 6.5 MEDIUM | Cisco Unified Communications Products Arbitrary File Read Vulnerability |
| CVE-2022-20778 | 6.1 MEDIUM | Cisco Webex Meetings Cross-Site Scripting Vulnerability |
| CVE-2022-20788 | 6.1 MEDIUM | Cisco Unified Communications Products Cross-Site Scripting Vulnerability |
| CVE-2022-20795 | 5.8 MEDIUM | Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense Software AnyConnect S |
| CVE-2022-20787 | 5.7 MEDIUM | Cisco Unified Communications Products Cross-Site Request Forgery Vulnerability |
| CVE-2022-20786 | 5.4 MEDIUM | Cisco Unified Communications Manager IM & Presence Service SQL Injection Vulnerability |
| CVE-2022-20804 | 5.3 MEDIUM | Cisco Unified Communications Products Denial of Service Vulnerability |
| CVE-2022-20789 | 4.9 MEDIUM | Cisco Unified Communications Products Arbitrary File Write Vulnerability |
| CVE-2022-20805 | 4.1 MEDIUM | Cisco Umbrella Secure Web Gateway File Decryption Bypass Vulnerability |
No comments yet