漏洞信息详情
Cisco Small Business 220 Series Smart Plus Switches 跨站请求伪造漏洞
漏洞简介
Cisco Small Business 220 Series Smart Plus Switches是美国思科(Cisco)公司的220系列可堆叠管理型交换机产品。
Cisco Small Business 220 Series Smart Plus Switches中的web-based管理界面存在跨站请求伪造漏洞。攻击者可利用该漏洞执行未授权操作。以下版本受到影响:运行1.0.0.17,1.0.0.18,1.0.0.19版本固件的Cisco Small Business 220 Series Smart Plus Switches。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-sps
参考网址
来源:CISCO
链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-sps
来源:BID
链接:http://www.securityfocus.com/bid/92709 来源:NSFOCUS 名称:34713 链接:http://www.nsfocus.net/vulndb/34713
受影响实体
- Cisco Small_business_220_series_smart_plus_switches:1.0.0.19<!--2000-1-1-->
- Cisco Small_business_220_series_smart_plus_switches:1.0.0.18<!--2000-1-1-->
- Cisco Small_business_220_series_smart_plus_switches:1.0.0.17<!--2000-1-1-->
补丁
- Cisco Small Business 220 Series Smart Plus Switches 跨站请求伪造漏洞的修复措施<!--2016-9-1-->
还没有评论,来说两句吧...