漏洞标题
N/A
漏洞描述信息
在运行ConfD的设备上,CLI(命令行接口)的实现中存在一个漏洞,该漏洞可能允许经过身份验证的本地攻击者执行命令注入攻击。此漏洞是由于受影响设备上对进程参数的验证不足所致。攻击者可以通过在该进程执行期间注入命令来利用此漏洞。成功利用此漏洞后,攻击者可以以ConfD的权限级别(通常是root)在底层操作系统上执行任意命令。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
漏洞标题
N/A
漏洞描述信息
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack.
The vulnerability is due to insufficient validation of a process argument on an affected device. An attacker could exploit this vulnerability by injecting commands during the execution of this process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privilege level of ConfD, which is commonly root.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
漏洞类别
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
漏洞标题
Cisco 多款产品操作系统命令注入漏洞
漏洞描述信息
Cisco Enterprise NFV Infrastructure Software(NFVIS)和Cisco Network Services Orchestrator(NSO)都是美国思科(Cisco)公司的产品。Cisco Enterprise NFV Infrastructure Software是一套NVF基础架构软件平台。该平台可以通过中央协调器和控制器实现虚拟化服务的全生命周期管理。Cisco Network Services Orchestrator是一套网络自动化服务解决方案。 Ci
CVSS信息
N/A
漏洞类别
授权问题