发布于3月6日3月6日 Members Cisco ASA: CVE-2024-20329: Cisco Adaptive Security Appliance Software SSH Remote Command Injection Vulnerability Severity 9 CVSS (AV:N/AC:L/Au:S/C:C/I:C/A:C) Published 10/23/2024 Created 10/25/2024 Added 10/24/2024 Modified 01/10/2025 Description A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by submitting crafted input when executing remote CLI commands over SSH. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system. Solution(s) cisco-asa-update-latest References https://attackerkb.com/topics/cve-2024-20329 CVE - 2024-20329 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ssh-rce-gRAuPEUF cisco-sa-asa-ssh-rce-gRAuPEUF
参与讨论
你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。