安全研究

安全漏洞
Cisco Aironet Access Points任意文件覆盖漏洞(CVE-2021-1423)

发布日期:2021-03-24
更新日期:2021-03-29

受影响系统:
Cisco Aironet 2800 Series Access Point
Cisco Integrated Access Point on 1100 Integrated Service
Cisco Aironet 1540 Series APs
Cisco Aironet 1560 Series APs
Cisco Aironet 1800 Series APs
Cisco Aironet 3800 Series APs
Cisco Aironet 4800 APs
Cisco Catalyst 9100 APs
Cisco Catalyst IW 6300 APs
Cisco 6300 Series Embedded Services APs
描述:
CVE(CAN) ID: CVE-2021-1423

Cisco Aironet Access Points(aps)是美国思科(Cisco)公司的一款网络接入点设备。
Cisco Aironet Access Points Software的CLI命令存在任意文件覆盖漏洞。该漏洞源于程序未对特定命令进行正确的输入验证。攻击者可通过发送特制的命令利用该漏洞覆盖设备闪存中的文件。

<*来源:Chris Bellows(Atredis Partners)
        HD Moore(Rumble)
  
  链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ap-foverwrt-HyVXvrtb
*>

建议:
厂商补丁:

Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-ap-foverwrt-HyVXvrtb)以及相应补丁:
cisco-sa-ap-foverwrt-HyVXvrtb:Cisco Aironet Access Points Arbitrary File Overwrite Vulnerability
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ap-foverwrt-HyVXvrtb

浏览次数:2094
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障