漏洞信息详情
多款Cisco产品访问控制错误漏洞
漏洞简介
Cisco Aironet 1540 Series APs等都是美国思科(Cisco)公司的产品。Cisco Aironet 1540 Series APs是一款1540系列访问接入点产品。Cisco Aironet 1560 Series APs是一款1560系列访问接入点产品。Cisco Aironet 1800 Series APs是一款1800系列访问接入点产品。
多款Cisco产品中的development shell(devshell)身份验证存在信任管理问题漏洞。该漏洞源于网络系统或产品中缺乏有效的信任管理机制。攻击者可利用默认密码或者硬编码密码、硬编码证书等攻击受影响组件。以下产品受到影响:Cisco Aironet 1540 SeriesAPs;Aironet 1560 Series APs;Aironet 1800 Series APs;Aironet 2800 Series APs;Aironet 3800 Series APs。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190417-aironet-shell
参考网址
来源:www.cisco.com
链接:http://www.cisco.com/
来源:BID
链接:http://www.securityfocus.com/bid/107991
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190417-air-ap-cmdinj
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190417-aironet-shell
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Cisco-Aironet-privilege-escalation-via-Development-Shell-29080
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79278
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.1329.2/
来源:www.securityfocus.com
链接:https://www.securityfocus.com/bid/107991
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-1654
受影响实体
暂无
补丁
- 多款Cisco产品信任管理问题漏洞的修复措施<!--2019-4-17-->
还没有评论,来说两句吧...