多款Cisco产品ASA Software和Firepower Threat Defense Software 输入验证错误漏洞

admin 2024-01-13 20:05:42 YS 来源:ZONE.CI 全球网 0 阅读模式
> 多款Cisco产品ASA Software和Firepower Threat Defense Software 输入验证错误漏洞

多款Cisco产品ASA Software和Firepower Threat Defense Software 输入验证错误漏洞

CNNVD-ID编号 CNNVD-201806-401 CVE编号 CVE-2018-0296
发布时间 2018-06-08 更新时间 2020-09-07
漏洞类型 路径遍历 漏洞来源 security researcher Michal Bentkowski from Securitum .,Angelo Ruwantha
危险等级 高危 威胁类型 远程
厂商 cisco

漏洞介绍

Cisco 3000 Series Industrial Security Appliance(ISA)等都是美国思科(Cisco)公司的安全设备。ASA Software和Firepower Threat Defense (FTD) Software都是分别运行在不同设备中的操作系统。

多款Cisco产品中的ASA Software和FTD Software的Web界面存在输入验证漏洞,该漏洞源于程序缺少对HTTP URL的正确验证。远程攻击者可通过向受影响设备发送特制的HTTP请求利用该漏洞造成拒绝服务或造成信息泄露。以下产品受到影响:Cisco 3000 Series Industrial Security Appliance (ISA);ASA 1000V Cloud Firewall;ASA 5500 Series Adaptive Security Appliances;ASA 5500-X Series Next-Generation Firewalls;ASA Services Module for Cisco Catalyst 6500 Series Switches和Cisco 7600 Series Routers;Adaptive Security Virtual Appliance (ASAv);Firepower 2100 Series Security Appliance;Firepower 4100 Series Security Appliance;Firepower 9300 ASA Security Module;FTD Virtual (FTDv)。

漏洞补丁

目前厂商已发布升级了多款Cisco产品ASA Software和Firepower Threat Defense Software 输入验证错误漏洞的补丁,多款Cisco产品ASA Software和Firepower Threat Defense Software 输入验证错误漏洞的补丁获取链接:

参考网址

来源:BID

链接:https://www.securityfocus.com/bid/104612

来源:MISC

链接:https://packetstormsecurity.com/files/154017/Cisco-Adaptive-Security-Appliance-Path-Traversal.html

来源:MISC

链接:https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01

来源:CONFIRM

链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-asaftd

来源:EXPLOIT-DB

链接:https://www.exploit-db.com/exploits/44956/

来源:SECTRACK

链接:http://www.securitytracker.com/id/1041076

来源:www.exploit-db.com

链接:https://www.exploit-db.com/exploits/47220

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/Cisco-ASA-denial-of-service-via-HTTP-URL-28680

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/154017/Cisco-Adaptive-Security-Appliance-Path-Traversal.html

受影响实体

Cisco Firepower_threat_defense:6.2.3.1 Cisco Firepower_threat_defense:6.2.3-851 Cisco Firepower_threat_defense:6.2.3-85.02 Cisco Firepower_threat_defense:6.2.3 Cisco Firepower_threat_defense:6.0.0

信息来源

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201806-401

weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论:0   参与:  0