漏洞标题
Cisco DNA Spaces:连接器命令注入漏洞
漏洞描述信息
思科DNA空间:连接器命令注入漏洞
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
Cisco DNA Spaces: Connector Command Injection Vulnerability
漏洞描述信息
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command. An attacker could exploit this vulnerability by including malicious input during the execution of the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as root.
CVSS信息
N/A
漏洞类别
输入验证不恰当
漏洞标题
Cisco DNA Spaces:Connector 操作系统命令注入漏洞
漏洞描述信息
Cisco DNA Spaces是美国思科(Cisco)公司的一套室内定位服务平台。Cisco DNA Spaces:Connector是其中的一个用于支持Cisco无线控制器通信的连接器。 Cisco DNA Spaces:Connector 2.0之前版本中存在操作系统命令注入漏洞,该漏洞源于程序没有对发送到CLI命令的参数进行充分的验证。本地攻击者可借助恶意的输入利用该漏洞在底层操作系统上以root权限执行任意命令。
CVSS信息
N/A
漏洞类别
授权问题