漏洞分享 - 思科產品存在多個漏洞
思科產品存在多個漏洞
一、摘要
思科產品存在多個漏洞,允許遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、繞過保安限制及跨網站指令碼。
二、存在風險
思科產品存在多個漏洞,允許遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、繞過保安限制及跨網站指令碼,其影響系統或版本如下:
- 受影響之系統:
- 250 Series Smart Switches
- 350 Series Managed Switches
- 350X Series Stackable Managed Switches
- 550X Series Stackable Managed Switches
- Business 250 Series Smart Switches
- Business 350 Series Managed Switches
- Cisco Unity Connection
- Unified Communications Manager (Unified CM) (CSCwd64245)
- Unified Communications Manager IM & Presence Service (Unified CM IM&P) (CSCwd64276)
- Unified Communications Manager Session Management Edition (Unified CM SME) (CSCwd64245)
- Unified Contact Center Express (UCCX) (CSCwe18773)
- Unity Connection (CSCwd64292)
- Virtualized Voice Browser (VVB) (CSCwe18840)
- 嚴重漏洞識別碼說明:
- CVE-2024-20305:此漏洞允許攻擊者於目標系統執行任意程式碼、存取敏感資料或瀏覽系統資訊。
- CVE-2024-20253:此漏洞允許攻擊者在作業系統上任意執行命令且也可以建議root存取的權限。
- CVE-2024-20263:此漏洞允許攻擊者繞過ACLs配置,並且導致流量遭到丟棄或轉發到不如預期之地方。
三、建議改善措施:
企業及使用者如有上述漏洞版本應盡速更新。
情資報告連結:
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuc-xss-9TFuu5MS
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-rce-bWNzQcUm
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-bus-acl-bypass-5zn9hNJk