Cisco VPN 3000 Series Concentrator XML Filter配置错误访问漏洞

漏洞信息详情

Cisco VPN 3000 Series Concentrator XML Filter配置错误访问漏洞

漏洞简介

Cisco VPN 3000 Concentrator 3.5.3之前的2.2.x,和3.x版本存在漏洞。当XML过滤器配置启用时,该软件添加一个\”HTTPS on Public Inbound (XML-Auto)(forward/in)\”准则但设置协议为\”ANY\”,最终导致任意通信通过集中器。

漏洞公告

Cisco has released fixes which address this issue. For Cisco VPN 3002 Hardware Client, this issue is addressed in versions 3.5.5 and 3.6.1 of the firmware.

Cisco VPN 3000 Concentrator 3.5 (Rel)

Cisco VPN 3000 Concentrator 3.5.1

Cisco VPN 3000 Concentrator 3.5.2

参考网址

来源: XF
名称: cisco-vpn-xml-filter(10023)
链接:http://www.iss.net/security_center/static/10023.php

来源: CISCO
名称: 20020903 Cisco VPN 3000 Concentrator Multiple Vulnerabilities
链接:http://www.cisco.com/warp/public/707/vpn3k-multiple-vuln-pub.shtml

来源: BID
名称: 5614
链接:http://www.securityfocus.com/bid/5614

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享