漏洞信息详情
Cisco Prime Infrastructure Software 信任管理问题漏洞
漏洞简介
Cisco Prime Infrastructure Software是美国思科(Cisco)公司的一套基础网络生命周期管理解决方案。该产品集成了Cisco Prime LAN Management Solution(LMS)和Cisco Prime Network Control System(NCS)。
Cisco Prime Infrastructure Software 2.2B版本至3.4.0版本中的 Identity Services Engine (ISE) integration功能存在信任管理问题漏洞,该漏洞源于程序没有正确地验证服务器SSL证书。远程攻击者可借助特制的SSL证书利用该漏洞实施中间人攻击,查看并修改敏感信息。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-prime-validation
参考网址
来源:CISCO
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-prime-validation
来源:BID
链接:https://www.securityfocus.com/bid/107092
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Cisco-Prime-Infrastructure-Man-in-the-Middle-via-SSL-Certificate-Not-Validated-28576
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-1659
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/75894
来源:www.nsfocus.net
链接:http://www.nsfocus.net/vulndb/42798
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-prime-validation
来源:www.securityfocus.com
链接:http://www.securityfocus.com/bid/107092
受影响实体
暂无
补丁
- Cisco Prime Infrastructure Software 安全漏洞的修复措施<!--2019-2-20-->
还没有评论,来说两句吧...