漏洞标题
N/A
漏洞描述信息
"novi_process_manager_daemon服务的网络接口,由于应用ACL修改时的 bug,可能会在操作员试图修改权限控制列表(ACL)时意外暴露。这可以被远程、未验证的攻击者利用,在交换机上实现特权(root)代码执行,因为 incoming packet data 可能包含嵌入的操作系统命令,并可以触发基于栈的缓冲溢出。"
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because incoming packet data can contain embedded OS commands, and can also trigger a stack-based buffer overflow.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
NoviFlow NoviWare和NoviSwitch设备安全漏洞
漏洞描述信息
NoviFlow NoviWare和NoviSwitch devices都是加拿大NoviFlow公司的产品。NoviSwitch devices是一系列交换机设备。NoviWare是使用在其中的交换机软件。 NoviFlow NoviWare NW400.2.6及之前的版本和NoviSwitch设备中的novi_process_manager_daemon的network界面存在安全漏洞。远程攻击者可利用该漏洞以root权限执行代码。
CVSS信息
N/A
漏洞类别
授权问题