漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Privileged escalation via crafted use of portcfg command
Vulnerability Description
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extension platforms: Brocade 7810, Brocade 7840, Brocade 7850 and on Brocade X6 or X7 directors with an SX-6 Extension blade installed. The attacker must be logged into the switch via SSH or serial console to conduct the attack.
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Broadcom Fabric OS 命令注入漏洞
Vulnerability Description
Broadcom Fabric OS(FOS)是美国博通(Broadcom)公司的一套使用在交换机和路由器等设备中的嵌入式操作系统。 Broadcom Fabric OS 9.2.0c版本和9.2.1至9.2.1a版本存在命令注入漏洞,该漏洞源于命令注入,可能导致经过身份验证的本地攻击者通过精心构造的portcfg命令使用进行特权升级。
CVSS Information
N/A
Vulnerability Type
N/A