CVE-2019-1681 (CNNVD-201902-799)
中文标题:
Cisco Network Convergence System 1000 Series IOS XR Software 信息泄露漏洞
英文标题:
Cisco Network Convergence System 1000 Series TFTP Directory Traversal Vulnerability
漏洞描述
中文描述:
Cisco Network Convergence System 1000 Series是美国思科(Cisco)公司的一款1000系列路由器。IOS XR Software是运行在其中的一套模块化、分布式的网络操作系统。 Cisco Network Convergence System 1000 Series中的IOS XR Software 6.5.2之前版本存在信息泄露漏洞,该漏洞源于程序没有正确地过滤TFTP请求中用户提交的输入。在TFTP服务被启用时,攻击者可通过向目标设备发送恶意的请求利用该漏洞检索设备上的任意文件。
英文描述:
A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could allow an unauthenticated, remote attacker to retrieve arbitrary files from the targeted device, possibly resulting in information disclosure. The vulnerability is due to improper validation of user-supplied input within TFTP requests processed by the affected software. An attacker could exploit this vulnerability by using directory traversal techniques in malicious requests sent to the TFTP service on a targeted device. An exploit could allow the attacker to retrieve arbitrary files from the targeted device, resulting in the disclosure of sensitive information. This vulnerability affects Cisco IOS XR Software releases prior to Release 6.5.2 for Cisco Network Convergence System 1000 Series devices when the TFTP service is enabled.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Network Convergence System 1000 Series | - | < 6.5.2 | - |
cpe:2.3:a:cisco:cisco_network_convergence_system_1000_series:*:*:*:*:*:*:*:*
|
| cisco | ios_xr | * | - | - |
cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-1681 |
2025-11-11 15:20:08 | 2025-11-11 07:35:37 |
| NVD | nvd_CVE-2019-1681 |
2025-11-11 14:56:20 | 2025-11-11 07:44:09 |
| CNNVD | cnnvd_CNNVD-201902-799 |
2025-11-11 15:10:10 | 2025-11-11 07:54:20 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信息泄露
- cnnvd_id: 未提取 -> CNNVD-201902-799
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']