Cisco APIC访问控制漏洞(CVE-2015-4235)
Cisco APIC访问控制漏洞(CVE-2015-4235)
Cisco APIC访问控制漏洞(CVE-2015-4235)
发布日期:2015-07-24
更新日期:2015-07-24
受影响系统:
Cisco Application Policy Infrastructure Controller < 1.1(1j)
Cisco Application Policy Infrastructure Controller < 1.0(4o)
Cisco Application Policy Infrastructure Controller < 1.0(3o)
描述:
CVE(CAN) ID: CVE-2015-4235
Cisco Application Policy Infrastructure Controller可以提供所有组构信息的集中访问服务,优化应用,支持应用配置。
Cisco APCI及Cisco Nexus 9000 Series ACI Mode Switch的集群管理配置存在漏洞,经过身份验证的远程攻击者利用此漏洞可以root用户权限访问APCI。此漏洞源于没有正确实现APIC文件系统内的访问控制。
<*来源:Cisco
链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-apic
*>
建议:
厂商补丁:
Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-20150722-apic)以及相应补丁:
cisco-sa-20150722-apic:Cisco Application Policy Infrastructure Controller Access Control Vulnerability
链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-apic
补丁下载:https://software.cisco.com/download/release.html?mdfid=285968390&softwareid=286278832&release=1.1%281j%29&relind=AVAILABLE&rellifecycle=&reltype=latest&i=rm
本文永久更新链接地址:
评论暂时关闭