发布日期:2023-04-05
更新日期:2023-06-25
受影响系统:
Cisco Cisco Evolved Programmable Network Manager
描述:
CVE(CAN) ID: CVE-2023-20121
Cisco Evolved Programmable Network Manager是美国思科(Cisco)公司的一套网络管理解决方案。
Cisco Evolved Programmable Network Manager存在操作系统命令注入漏洞,经过身份认证的本地攻击者可利用该漏洞转义受限的shell并获取根权限。
< *链接:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-adeos-MLAyEcv
*>
建议:
厂商补丁:
Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-adeos-MLAyEcvk)以及相应补丁:
cisco-sa-adeos-MLAyEcvk:Cisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection Vulnerabilities
链接:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-adeos-MLAyEcvk
浏览次数:31
严重程度:0(网友投票)