目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2023-20100— Cisco IOS XE Software 安全漏洞

CVSS 6.8 · Medium EPSS 1.08% · P78
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2023-20100の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Cisco IOS XE Software for Wireless LAN Controllers CAPWAP Join Denial of Service Vulnerability
ソース: NVD (National Vulnerability Database)
脆弱性説明
A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error that occurs when certain conditions are met during the AP joining process. An attacker could exploit this vulnerability by adding an AP that is under their control to the network. The attacker then must ensure that the AP successfully joins an affected wireless controller under certain conditions. Additionally, the attacker would need the ability to restart a valid AP that was previously connected to the controller. A successful exploit could allow the attacker to cause the affected device to restart unexpectedly, resulting in a DoS condition.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
使用多个具有重复标识的资源
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Cisco IOS XE Software 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Cisco IOS XE Software是美国思科(Cisco)公司的一个操作系统。用于企业有线和无线访问,汇聚,核心和WAN的单一操作系统,Cisco IOS XE降低了业务和网络的复杂性。 Cisco IOS XE Software 存在安全漏洞,该漏洞源于AP加入过程中满足某些条件时发生的逻辑错误。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
CiscoCisco IOS XE Software n/a -

II. CVE-2023-20100の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2023-20100のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Cisco · 2023-03-23 · 18 CVEs total

CVE-2023-200278.6 HIGHCisco IOS XE Software Virtual Fragmentation Reassembly Denial of Service Vulnerability
CVE-2023-200808.6 HIGHCisco IOS and IOS XE Software IPv6 DHCP (DHCPv6) Relay and Server Denial of Service Vulner
CVE-2023-200728.6 HIGHCisco IOS XE Software Fragmented Tunnel Protocol Packet Denial of Service Vulnerability
CVE-2023-200558.0 HIGHCisco DNA Center Privilege Escalation Vulnerability
CVE-2023-200357.8 HIGHCisco IOS XE SD-WAN Software Command Injection Vulnerability
CVE-2023-200657.8 HIGHCisco IOS XE Software 安全漏洞
CVE-2023-201127.4 HIGHCisco Access Point Software Association Request Denial of Service Vulnerability
CVE-2023-200677.4 HIGHCisco IOS XE Software for Wireless LAN Controllers HTTP Client Profiling Denial of Service
CVE-2023-200816.8 MEDIUMCisco Adaptive Security Appliance Software, Firepower Threat Defense Software, IOS Softwar
CVE-2023-201136.5 MEDIUMCisco SD-WAN vManage Software Cross-Site Request Forgery Vulnerability
CVE-2023-200666.5 MEDIUMCisco IOS XE Software Web UI Path Traversal Vulnerability
CVE-2023-200566.5 MEDIUMCisco Access Point Software Denial of Service Vulnerability
CVE-2023-200826.1 MEDIUMCisco IOS XE Software for Cisco Catalyst 9300 Series Switches Secure Boot Bypass Vulnerabi
CVE-2023-200974.6 MEDIUMCisco Access Point Software Command Injection Vulnerability
CVE-2023-200294.4 MEDIUMCisco IOS XE Software Privilege Escalation Vulnerability
CVE-2023-200594.3 MEDIUMCisco DNA Center Information Disclosure Vulnerability
CVE-2023-20107Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entro

IV. 関連脆弱性

V. CVE-2023-20100へのコメント

まだコメントはありません


コメントを残す