Cisco多个产品多个CVE漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

>> Multiple critical vulnerabilities in Cisco UCS Director, Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data >> Discovered by Pedro Ribeiro (pedrib@gmail.com) from Agile Information Security Disclosure: 21/08/2019 / Last updated: 22/08/2019 >> Executive summary: Cisco UCS Director (UCS) is a cloud orchestration product that automates common private cloud infrastructure management functions. It is built using Java and a variety of other technologies and distributed as a Linux based virtual appliance. A demo of the UCS virtual appliance can be freely downloaded from Cisco's website [1]. Due to several coding errors, it is possible for an unauthenticated remote attacker with no privileges to bypass authentication and abuse a password change function to inject arbitrary commands and execute code as root. In addition, there is a default unprivileged user with a known password that can login via SSH and execute commands on the virtual...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息