Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled. This vulnerability is due to insufficient user session management within the Cisco Catalyst SD-WAN Manager system. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain unauthorized access to information about another tenant, make configuration changes, or possibly take a tenant offline causing a denial of service condition.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Cisco Catalyst 安全漏洞
Vulnerability Description
Cisco Catalyst是美国思科(Cisco)公司的一系列交换机。 Cisco Catalyst SD-WAN Manager 存在安全漏洞,该漏洞源于多租户功能的会话管理系统中存在漏洞,可能允许经过身份验证的远程攻击者访问由同一 Cisco Catalyst SD-WAN Manager 实例管理的另一个租户。
CVSS Information
N/A
Vulnerability Type
N/A