漏洞信息详情
Cisco Unified Customer Voice Portal Software 权限许可和访问控制问题漏洞
漏洞简介
Cisco Unified Customer Voice Portal(CVP)是美国思科(Cisco)公司的一套用于提供语音和视频自助服务的统一通信系统。
Cisco Unified Customer Voice Portal (CVP) Software Release 11.6(1) ES-11之前版本和Release 12.0(1) ES-7之前版本中的Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server存在权限许可和访问控制问题漏洞,该漏洞源于程序没有进行充分的输入验证。远程攻击者可通过向Cisco Unified CVP进行身份验证并发送特制的HTTP请求利用该漏洞获取被限制的信息并可能修改被限制资源的配置信息。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200108-cvp-direct-obj-ref
参考网址
来源:CISCO
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200108-cvp-direct-obj-ref
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200108-cvp-direct-obj-ref
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0092/
受影响实体
暂无
补丁
- Cisco Unified Customer Voice Portal Software Operations, Administration, Maintenance and Provisioning OpsConsole Server 权限许可和访问控制问题漏洞的修复措施<!--2020-1-8-->
还没有评论,来说两句吧...