cisco aironet_1542i_firmware 跨站请求伪造(csrf)
CVE编号
CVE-2020-3261利用情况
暂无补丁情况
N/A披露时间
2020-04-16漏洞描述
Cisco Mobility Express Software是美国思科(Cisco)公司的一套使用在Cisco无线接入点设备中的软件。 Cisco Mobility Express Software中的基于Web的管理接口存在跨站请求伪造漏洞。攻击者可通过诱使用户点击恶意链接利用该漏洞进行任意操作。解决建议
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mob-exp-csrf-b8tFec24
参考链接 |
|
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-s... |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
系统 | cisco | 6300_series_access_points_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | 6300_series_access_points_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1542d_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1542d_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1542i_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1542i_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1562d_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1562d_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1562e_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1562e_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1562i_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1562i_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1815_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1815_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1830_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1830_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1840_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1840_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1850_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_1850_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_2800e_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_2800e_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_2800i_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_2800i_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3800e_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3800e_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3800i_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3800i_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3800p_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3800p_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_4800_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_4800_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | catalyst_iw6300_firmware | * | From (including) 8.0 | Up to (excluding) 8.8.130.0 | ||||
运行在以下环境 | |||||||||
系统 | cisco | catalyst_iw6300_firmware | 8.10(1.255) | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | 6300_series_access_points | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_1542d | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_1542i | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_1562d | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_1562e | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_1562i | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_1815 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_1830 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_1840 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_1850 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_2800e | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_2800i | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_3800e | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_3800i | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_3800p | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_4800 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | catalyst_iw6300 | - | - | |||||
- 攻击路径 网络
- 攻击复杂度 低
- 权限要求 无
- 影响范围 未更改
- 用户交互 需要
- 可用性 无
- 保密性 无
- 完整性 高
CWE-ID | 漏洞类型 |
CWE-352 | 跨站请求伪造(CSRF) |
Exp相关链接

版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论