漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, remote attacker to download or overwrite files from the underlying operating system of an affected device. This vulnerability is due to a logic error when verifying the user role when an SFTP connection is opened to an affected device. An attacker could exploit this vulnerability by connecting and authenticating via SFTP as a valid, non-administrator user. A successful exploit could allow the attacker to read or overwrite files from the underlying operating system with the privileges of the authenticated user. There are workarounds that address this vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
缺乏对安全的管理控制
Vulnerability Title
Cisco Nexus Series Switches 安全漏洞
Vulnerability Description
Cisco Nexus 3000 Series Switches是美国思科(Cisco)公司的一款3000系列交换机。 Cisco Nexus Series Switches存在安全漏洞,该漏洞源于在独立NX-OS模式下,SFTP服务器允许攻击者从底层操作系统下载或覆盖文件。受影响的产品:Cisco Nexus 3000 Series Switches和9000 Series Switches。
CVSS Information
N/A
Vulnerability Type
N/A