安全研究
安全漏洞
多款Cisco Small Business Series Switches信息泄露漏洞(CVE-2021-34739)
发布日期:2021-11-03
更新日期:2021-11-05
受影响系统:Cisco 550X Series Stackable Managed Switches
Cisco Small Business 300 Series Managed Switches
Cisco Small Business 200 Series Smart Switches
Cisco 250 Series Smart Switches
Cisco 350 Series Managed Switches
Cisco 350X Series Stackable Managed Switches
Cisco Small Business 500 Series Stackable Managed Switches
Cisco Business 250 Series Smart Switches
Cisco Business 350 Series Managed Switches
Cisco ESW2 Series Advanced Switches
描述:
CVE(CAN) ID:
CVE-2021-34739
思科精睿(Cisco Small Business)是思科公司针对中小企业定制化推出的一系列完整解决方案及产品。
多款Cisco Small Business Series Switches的Web管理界面存在信息泄露漏洞。该漏洞源于会话凭据到期时间不足。未经身份认证远程攻击者可利用该漏洞重放有效的用户会话凭据,并未经授权访问受影响设备。
<*链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-switches-tokens-U
*>
建议:
厂商补丁:
Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-smb-switches-tokens-UzwpR4e5)以及相应补丁:
cisco-sa-smb-switches-tokens-UzwpR4e5:Cisco Small Business Series Switches Session Credentials Replay Vulnerability
链接:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-switches-tokens-UzwpR4e5浏览次数:3009
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载 绿盟科技给您安全的保障 |