目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2021-1572— Cisco ConfD 安全漏洞

CVSS 7.8 · High EPSS 0.25% · P16
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2021-1572 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ConfD CLI Secure Shell Server Privilege Escalation Vulnerability
来源: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root. To exploit this vulnerability, an attacker must have a valid account on an affected device. The vulnerability exists because the affected software incorrectly runs the SFTP user service at the privilege level of the account that was running when the ConfD built-in Secure Shell (SSH) server for CLI was enabled. If the ConfD built-in SSH server was not enabled, the device is not affected by this vulnerability. An attacker with low-level privileges could exploit this vulnerability by authenticating to an affected device and issuing a series of commands at the SFTP interface. A successful exploit could allow the attacker to elevate privileges to the level of the account under which ConfD is running, which is commonly root. Note: Any user who can authenticate to the built-in SSH server may exploit this vulnerability. By default, all ConfD users have this access if the server is enabled. Software updates that address this vulnerability have been released.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
特权授予不正确
来源: CVE Program / CVE List V5
Vulnerability Title
Cisco ConfD 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Cisco ConfD是美国思科(Cisco)公司的一个管理软件。 Cisco ConfD存在安全漏洞,该漏洞源于受影响的软件以特权用户启用CLI的ConfD内置SSH服务器时运行的情况下错误地运行SFTP用户服务。该漏洞允许经过身份验证的本地攻击者在远行ConfD的账户中执行任意命令,并且可以通过对受影响的设备进行身份验证并在SFTP接口发送一系列命令将账户权限提升到特权用户。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
CiscoCisco ConfD n/a -

二、漏洞 CVE-2021-1572 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-1572 的情报信息

登录查看更多情报信息。

CVE-2021-1572 厂商安全公告 (2)

同批安全公告 · Cisco · 2021-08-04 · 共 7 条

CVE-2021-16109.8 CRITICALCisco Small Business RV340和Cisco Small Business 命令注入漏洞
CVE-2021-16099.8 CRITICALCisco Small Business RV340和Cisco Small Business 安全漏洞
CVE-2021-16028.2 HIGHCisco Small Business 操作系统命令注入漏洞
CVE-2021-15937.3 HIGHCisco Packet Tracer代码问题漏洞
CVE-2021-347076.5 MEDIUMCisco Evolved Programmable Network Manager 信息泄露漏洞
CVE-2021-15224.3 MEDIUMCisco Connected Mobile Experiences 信任管理问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-1572

暂无评论


发表评论