漏洞标题
N/A
漏洞描述信息
Cisco IOS Software 和 Cisco IOS XE Software 中的 Cisco Group Encrypted Transport VPN(GET VPN)功能中的一个漏洞可能会让具有管理权限的远程攻击者在一个受影响的设备上执行任意代码,或者导致设备崩溃。
这个漏洞是由于 GET VPN 功能中的 GDOI 和 G-IKEv2 协议对属性的验证不足。攻击者可以通过 either compromising an installed key server 或者修改一个受攻击者控制的组员的配置来利用这个漏洞。一个成功的利用可能导致攻击者执行任意代码并完全控制受影响的系统,或者导致受影响的系统重新加载,从而导致拒绝服务(DoS)条件。更多信息,请参阅本警告的详细信息 ["#details"] 部分。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
输入验证不恰当
漏洞标题
N/A
漏洞描述信息
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash.
This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. For more information, see the Details ["#details"] section of this advisory.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
跨界内存写
漏洞标题
Cisco IOS 缓冲区错误漏洞
漏洞描述信息
Cisco IOS是美国思科(Cisco)公司的一套为其网络设备开发的操作系统。 Cisco IOS 软件和 Cisco IOS XE存在安全漏洞,该漏洞源于Cisco Group Encrypted Transport VPN (GET VPN) 功能中的漏洞可能允许对组成员或密钥服务器具有管理控制权的经过身份验证的远程攻击者在受影响的设备或导致设备崩溃。
CVSS信息
N/A
漏洞类别
缓冲区错误