Cisco Cisco Crosswork Network Change Automation是美国Cisco公司的网络设备自动化管理软件。 Cisco Crosswork Network Change Automation存在输入验证错误漏洞,该漏洞源于基于Web的管理界面配置模板引擎存在输入验证不足,可能允许经过身份验证的远程攻击者通过发送特制请求,在底层操作系统的文件系统有限区域内执行任意命令。以下版本受到影响:1.0.0版本、2.0.0版本、2.0.1版本、2.0.2版本、3.0.0版本、3.0.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Crosswork Network Change Automation | 3.0.0 |
affected |
3.0.1 |
affected | ||
1.0.0 |
affected | ||
2.0.0 |
affected | ||
2.0.1 |
affected | ||
3.0.2 |
affected | ||
2.0.2 |
affected | ||
3.0.3 |
affected | ||
| … +29 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Crosswork Network Change Automation | 3.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20181 | 9.1 CRITICAL | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20190 | 7.5 HIGH | Cisco Identity Services Engine Information Disclosure Vulnerability |
| CVE-2026-20246 | 6.0 MEDIUM | Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability |
| CVE-2026-20178 | 4.3 MEDIUM | Cisco Webex App 输入验证错误漏洞 |
No comments yet