发布日期:2023-06-28
更新日期:2023-08-24
受影响系统:
Cisco Cisco Small Business 200 Series Smart Switches 1.4.11.02
Cisco Cisco Small Business 300 Series Managed Switches 1.4.11.02
Cisco Cisco Small Business 500 Series Stackable Managed 1.4.11.02
描述:
CVE(CAN) ID: CVE-2023-20188
Cisco Small Business 200 Series Smart Switches等都是美国思科(Cisco)公司的系列交换机设备。
Cisco Small Business 200 Series Smart Switches、Small Business 300 Series Managed Switches、Small Business 500 Series Stackable Managed Switches 1.4.11.02版本存在跨站脚本漏洞,该漏洞源于程序未对用户输入进行正确验证,经过身份认证的远程攻击者可利用该漏洞以受影响页面权限执行脚本代码或访问浏览器的敏感信息。
< *链接:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-sxss-OPYJ
*>
建议:
厂商补丁:
Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-smb-sxss-OPYJZUmE)以及相应补丁:
cisco-sa-smb-sxss-OPYJZUmE:Cisco Small Business 200, 300, and 500 Series Switches Web-Based Management Stored Cross-Site Scripting Vulnerability
链接:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-sxss-OPYJZUmE
浏览次数:38
严重程度:0(网友投票)