脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers IPSec VPN Server Authentication Bypass Vulnerability
脆弱性説明
A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to bypass authentication controls and access the IPSec VPN network. This vulnerability is due to the improper implementation of the password validation algorithm. An attacker could exploit this vulnerability by logging in to the VPN from an affected device with crafted credentials. A successful exploit could allow the attacker to bypass authentication and access the IPSec VPN network. The attacker may obtain privileges that are the same level as an administrative user, depending on the crafted credentials that are used. Cisco has not released software updates that address this vulnerability.
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
脆弱性タイプ
认证算法的不正确实现
脆弱性タイトル
Cisco Small Business 授权问题漏洞
脆弱性説明
Cisco Small Business是美国思科(Cisco)公司的一个交换机。 Cisco Small Business RV110W、RV130、RV130W 和 RV215W 路由器存在安全漏洞,该漏洞源于IPSec VPN 服务器身份验证功能中存在一个漏洞,攻击者利用该漏洞可以绕过身份验证控制并访问 IPSec VPN 网络。
CVSS情報
N/A
脆弱性タイプ
N/A