漏洞标题
Cisco连接的移动体验信息泄露漏洞
漏洞描述信息
Cisco Connected Mobile Experiences(CMX)软件中的一个漏洞可能允许未经过身份验证的相邻攻击者访问受影响设备上的敏感数据。该漏洞是由于受影响设备上某些API的GET请求缺乏输入和验证检查机制造成的。攻击者可能通过向受影响设备发送HTTP GET请求来利用此漏洞。该漏洞可能允许攻击者利用这些信息进行额外的侦察攻击。
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
漏洞类别
N/A
漏洞标题
Cisco Connected Mobile Experiences Information Disclosure Vulnerability
漏洞描述信息
A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device. The vulnerability is due to a lack of input and validation checking mechanisms for certain GET requests to API's on an affected device. An attacker could exploit this vulnerability by sending HTTP GET requests to an affected device. An exploit could allow the attacker to use this information to conduct additional reconnaissance attacks.
CVSS信息
N/A
漏洞类别
信息暴露
漏洞标题
Cisco Connected Mobile Experiences Software 信息泄露漏洞
漏洞描述信息
Cisco Connected Mobile Experiences(CMX)Software是美国思科(Cisco)公司的一套互联移动体验解决方案。 Cisco CMX Software中存在信息泄露漏洞,该漏洞源于程序缺少对GET请求的验证和输入检查机制。攻击者可通过发送HTTP GET请求利用该漏洞访问敏感数据。
CVSS信息
N/A
漏洞类别
信息泄露