Cisco Security Advisory 2024年07月05日
Cisco Firepower Management Center Software SQL Injection Vulnerability
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Cisco Firepower Management Center (FMC) 软件的基于 Web 的管理界面中存在一个漏洞,该漏洞可能允许经过身份验证的远程攻击者对受影响的系统进行 SQL 注入攻击。此漏洞存在的原因是基于 Web 的管理界面没有充分验证用户输入。攻击者可以通过向受影响的系统发送精心制作的 SQL 查询来利用此漏洞。成功利用此漏洞可能允许攻击者从数据库中获取任何数据,在底层操作系统上执行任意命令,并将权限提升为 root。为了利用此漏洞,攻击者至少需要只读用户凭据。

😨 **漏洞描述:** Cisco Firepower Management Center (FMC) 软件的基于 Web 的管理界面中存在一个漏洞,该漏洞可能允许经过身份验证的远程攻击者对受影响的系统进行 SQL 注入攻击。 漏洞存在的原因是基于 Web 的管理界面没有充分验证用户输入。攻击者可以通过向受影响的系统发送精心制作的 SQL 查询来利用此漏洞。成功利用此漏洞可能允许攻击者从数据库中获取任何数据,在底层操作系统上执行任意命令,并将权限提升为 root。 为了利用此漏洞,攻击者至少需要只读用户凭据。

😥 **漏洞影响:** 攻击者可以利用此漏洞从数据库中获取任何数据,在底层操作系统上执行任意命令,并将权限提升为 root。

😄 **解决方案:** Cisco 已发布了解决此漏洞的软件更新。没有解决此漏洞的变通方法。

😎 **安全建议:** 请尽快更新您的 Cisco Firepower Management Center (FMC) 软件到最新版本,以修复此漏洞。

🥳 **漏洞信息:** 此漏洞的 CVE 编号为 CVE-2024-20360。

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.

This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials. 

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sqli-WFFDnNOs

This advisory is part of the May 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: May 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.


Security Impact Rating: High
CVE: CVE-2024-20360

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Cisco Firepower Management Center FMC SQL 注入 漏洞 安全更新
相关文章