Cisco APIC访问控制漏洞(CVE-2015-4235)


Cisco APIC访问控制漏洞(CVE-2015-4235)


发布日期:2015-07-24
更新日期:2015-07-24

受影响系统:

Cisco Application Policy Infrastructure Controller < 1.1(1j)
Cisco Application Policy Infrastructure Controller < 1.0(4o)
Cisco Application Policy Infrastructure Controller < 1.0(3o)

描述:


CVE(CAN) ID: CVE-2015-4235

Cisco Application Policy Infrastructure Controller可以提供所有组构信息的集中访问服务,优化应用,支持应用配置。

Cisco APCI及Cisco Nexus 9000 Series ACI Mode Switch的集群管理配置存在漏洞,经过身份验证的远程攻击者利用此漏洞可以root用户权限访问APCI。此漏洞源于没有正确实现APIC文件系统内的访问控制。

<*来源:Cisco
 
  链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-apic
*>

建议:


厂商补丁:

Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-20150722-apic)以及相应补丁:
cisco-sa-20150722-apic:Cisco Application Policy Infrastructure Controller Access Control Vulnerability
链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-apic

补丁下载:https://software.cisco.com/download/release.html?mdfid=285968390&softwareid=286278832&release=1.1%281j%29&relind=AVAILABLE&rellifecycle=&reltype=latest&i=rm

本文永久更新链接地址

相关内容

    暂无相关文章