漏洞名称:Cisco APIC访问控制漏洞(CVE-2015-4235)
发表日期:2015-07-27 13:52:17
漏洞名称:Cisco APIC访问控制漏洞(CVE-2015-4235)
CVE ID:CVE-2015-4235
受影响系统:
Cisco Application Policy Infrastructure Controller < 1.1(1j)
Cisco Application Policy Infrastructure Controller < 1.0(4o)
Cisco Application Policy Infrastructure Controller < 1.0(3o)
详细信息:
Cisco Application Policy Infrastructure Controller可以提供所有组构信息的集中访问服务,优化应用,支持应用配置。
Cisco APCI及Cisco Nexus 9000 Series ACI Mode Switch的集群管理配置存在漏洞,经过身份验证的远程攻击者利用此漏洞可以root用户权限访问APCI。此漏洞源于没有正确实现APIC文件系统内的访问控制。
漏洞来源:
Cisco
解决方案:
厂商补丁:
Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-20150722-apic)以及相应补丁:
cisco-sa-20150722-apic:Cisco Application Policy Infrastructure Controller Access Control Vulnerability
链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-apic
补丁下载:https://software.cisco.com/download/release.html?mdfid=285968390&softwareid=286278832&release=1.1%281j%29&relind=AVAILABLE&rellifecycle=&reltype=latest&i=rm