漏洞标题
Cisco Redundancy Configuration Manager调试信息泄露漏洞
漏洞描述信息
在Cisco RCM for Cisco StarOS软件的一个调试功能中存在漏洞,这可能允许未经过身份验证的远程攻击者执行调试操作,导致泄露本应受到限制的机密信息。
此漏洞的存在是因为一个调试服务错误地监听并接受传入连接。攻击者可以通过连接到调试端口并执行调试命令来利用此漏洞。成功利用此漏洞可能会使攻击者查看敏感的调试信息。Cisco已发布了修复此漏洞的软件更新。目前没有解决此漏洞的变通方法。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
将资源暴露给错误范围
漏洞标题
Cisco Redundancy Configuration Manager Debug Information Disclosure Vulnerability
漏洞描述信息
A vulnerability in a debug function for Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform debug actions that could result in the disclosure of confidential information that should be restricted.
This vulnerability exists because of a debug service that incorrectly listens to and accepts incoming connections. An attacker could exploit this vulnerability by connecting to the debug port and executing debug commands. A successful exploit could allow the attacker to view sensitive debugging information.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
漏洞类别
信息暴露
漏洞标题
Cisco Redundancy Configuration Manager for Cisco StarOS 信息泄露漏洞
漏洞描述信息
Redundancy Configuration Manager For Cisco StarOS(Rcm For Cisco StarOS)是美国思科(Cisco)公司的一个冗余配置管理器。 Cisco Redundancy Configuration Manager for Cisco StarOS存在信息泄露漏洞,该漏洞源于调试服务不正确地监听和接受传入的连接。远程攻击者可利用该漏洞可以访问敏感的调试信息。
CVSS信息
N/A
漏洞类别
信息泄露