目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2019-1890— Cisco Nexus 9000 Series Fabric Switches 访问控制错误漏洞

AI Predicted 8.1 Difficulty: Moderate EPSS 0.63% · P47
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2019-1890の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Cisco Nexus 9000 Series Fabric Switches ACI Mode Fabric Infrastructure VLAN Unauthorized Access Vulnerability
ソース: CVE Program / CVE List V5
脆弱性説明
A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. The vulnerability is due to insufficient security requirements during the Link Layer Discovery Protocol (LLDP) setup phase of the infrastructure VLAN. An attacker could exploit this vulnerability by sending a malicious LLDP packet on the adjacent subnet to the Cisco Nexus 9000 Series Switch in ACI mode. A successful exploit could allow the attacker to connect an unauthorized server to the infrastructure VLAN, which is highly privileged. With a connection to the infrastructure VLAN, the attacker can make unauthorized connections to Cisco Application Policy Infrastructure Controller (APIC) services or join other host endpoints.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
访问控制不恰当
ソース: CVE Program / CVE List V5
脆弱性タイトル
Cisco Nexus 9000 Series Fabric Switches 访问控制错误漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Cisco Nexus 9000 Series Fabric Switches是美国思科(Cisco)公司的一款9000系列光纤交换机。 Cisco Nexus 9000 Series Fabric Switches(处于ACI模式)中建立fabric infrastructure VLAN链接的过程存在访问控制错误漏洞。攻击者可通过在临近的子节点上向Cisco Nexus 9000 Series Switch发送恶意的LLDP数据包利用该漏洞绕过安全限制并将未授权的服务器连接到基础设施的VLAN。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
CiscoCisco NX-OS System Software in ACI Mode 11.0.1b unspecified ~ 14.1(2g) -

II. CVE-2019-1890の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2019-1890のインテリジェンス情報

登录查看更多情报信息。

CVE-2019-1890 厂商安全公告 (2)

Same Patch Batch · Cisco · 2019-07-04 · 5 CVEs total

CVE-2019-1889Cisco Application Policy Infrastructure Controller REST API Privilege Escalation Vulnerabi
CVE-2019-1855Cisco Jabber for Windows DLL Preloading Vulnerability
CVE-2019-1884Cisco Web Security Appliance Web Proxy Denial of Service Vulnerability
CVE-2019-1886Cisco Web Security Appliance HTTPS Certificate Denial of Service Vulnerability

IV. 関連脆弱性

V. CVE-2019-1890へのコメント

まだコメントはありません


コメントを残す