Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cisco Secure Network Analytics API Authorization Vulnerability
Vulnerability Description
A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to generate fraudulent findings that are used to generate alarms and alerts on an affected product. Thi vulnerability is due to insufficient authorization enforcement on a specific API. An attacker could exploit this vulnerability by authenticating as a low-privileged user and performing API calls with crafted input. A successful exploit could allow the attacker to obfuscate legitimate findings in analytics reports or create false indications with alarms and alerts on an affected device.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Cisco Secure Network Analytics Manager和Cisco Secure Network Analytics Virtual Manager 安全漏洞
Vulnerability Description
Cisco Secure Network Analytics Manager和Cisco Secure Network Analytics Virtual Manager都是美国思科(Cisco)公司的产品。Cisco Secure Network Analytics Manager是一个安全网络分析管理器。Cisco Secure Network Analytics Virtual Manager是一个安全网络分析虚拟管理器。 Cisco Secure Network Analytics Manager
CVSS Information
N/A
Vulnerability Type
N/A