漏洞标题
思科UCS Director路径遍历漏洞
漏洞描述信息
思科UCS Director路径遍历漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
漏洞类别
N/A
漏洞标题
Cisco UCS Director Path Traversal Vulnerability
漏洞描述信息
A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input on the web-based management interface. An attacker could exploit this vulnerability by creating a task with specific configuration parameters. A successful exploit could allow the attacker to overwrite arbitrary files in the file system of an affected device.
CVSS信息
N/A
漏洞类别
对路径名的限制不恰当(路径遍历)
漏洞标题
Cisco UCS Director 路径遍历漏洞
漏洞描述信息
Cisco UCS Director是美国思科(Cisco)公司的一套私有云基础架构即服务(IaaS)的异构平台。 Cisco UCS Director Release 6.7.4.0之前版本中orchestration任务存在路径遍历漏洞,该漏洞源于程序没有充分验证用户提交的输入。远程攻击者可通过特定的配置参数创建任务利用该漏洞覆盖文件系统中的任意文件。
CVSS信息
N/A
漏洞类别
路径遍历