安全研究

安全漏洞
Cisco Application Policy Infrastructure Controller本地权限提升漏洞(CVE-2019-1682)

发布日期:2019-05-01
更新日期:2019-05-05

受影响系统:
Cisco Application Policy Infrastructure Controller 3.2(2l)
Cisco Application Policy Infrastructure Controller 2.3(1f)
Cisco Application Policy Infrastructure Controller 2.2(1)
Cisco Application Policy Infrastructure Controller 2.1(1h)
Cisco Application Policy Infrastructure Controller 2.0(2f)
Cisco Application Policy Infrastructure Controller 1.3(2f)
不受影响系统:
Cisco Application Policy Infrastructure Controller 4.1(1i)
描述:
BUGTRAQ  ID: 108129
CVE(CAN) ID: CVE-2019-1682

Cisco Application Policy Infrastructure Controller(APIC)是美国思科(Cisco)公司的一款自动化的基础架构部署和治理解决方案。
Cisco Application Policy Infrastructure Controller(APIC)软件的FUSE文件系统功能存在一个漏洞,可能允许经过身份验证的本地攻击者将权限升级到受影响设备上的root用户。

<*来源:Octav Opaschi with Detack GmbH
  
  链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-apic-priv-es
*>

建议:
厂商补丁:

Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-20190501-apic-priv-escalation)以及相应补丁:
cisco-sa-20190501-apic-priv-escalation:Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-apic-priv-es

浏览次数:1373
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障