跳转到帖子

Cisco Catalyst SD-WAN: CVE-2023-20098: Cisco SD-WAN vManage Software Arbitrary File Deletion Vulnerability

recommended_posts

发布于
  • Members

Cisco Catalyst SD-WAN: CVE-2023-20098: Cisco SD-WAN vManage Software Arbitrary File Deletion Vulnerability

Severity
4
CVSS
(AV:L/AC:L/Au:M/C:N/I:C/A:N)
Published
04/19/2023
Created
07/02/2024
Added
06/25/2024
Modified
08/29/2024

Description

A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with administrative privileges could exploit this vulnerability by running a system command containing directory traversal character sequences to target an arbitrary file. A successful exploit could allow the attacker to delete arbitrary files from the system, including files owned by root.

Solution(s)

  • cisco-catalyst-sdwan-update-latest

References

  • https://attackerkb.com/topics/cve-2023-20098
  • CVE - 2023-20098
  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vmanage-wfnqmYhN
  • cisco-sa-sdwan-vmanage-wfnqmYhN
  • 查看数 695
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…