漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cisco IOS XE ROM Monitor Software for Catalyst Switches Information Disclosure Vulnerability
Vulnerability Description
A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. This vulnerability is due to a problem with the file and boot variable permissions in ROMMON. An attacker could exploit this vulnerability by rebooting the switch into ROMMON and entering specific commands through the console. A successful exploit could allow the attacker to read any file or reset the enable password.
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
文件和路径信息暴露
Vulnerability Title
Cisco Catalyst 安全漏洞
Vulnerability Description
Cisco Catalyst是美国思科(Cisco)公司的一系列交换机。 Cisco Catalyst 的 Cisco IOS XE ROM Monitor 存在安全漏洞,该漏洞源于在ROMMON中出现文件和引导变量权限问题。攻击者利用该漏洞可以读取任何文件或重置启用密码。
CVSS Information
N/A
Vulnerability Type
N/A