CVE-2017-12263 (CNNVD-201710-055)
中文标题:
Cisco License Manager software 路径遍历漏洞
英文标题:
A vulnerability in the web interface of Cisco License Manager software could allow an unauthenticate...
漏洞描述
中文描述:
Cisco License Manager software是美国思科(Cisco)公司的一套许可证书管理软件。该软件用于激活Cisco设备及软件,并在线获取设备许可证或产品秘钥。 Cisco License Manager software中的Web界面存在路径遍历漏洞,该漏洞源于程序没有正确的过滤HTTP请求参数中用户的输入。远程攻击者可利用该漏洞下载并查看应用程序中的文件。
英文描述:
A vulnerability in the web interface of Cisco License Manager software could allow an unauthenticated, remote attacker to download and view files within the application that should be restricted, aka Directory Traversal. The issue is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. An exploit could allow the attacker to view application files that may contain sensitive information. Cisco Bug IDs: CSCvd83577.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | license_manager | 3.2.6 | - | - |
cpe:2.3:a:cisco:license_manager:3.2.6:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-12263 |
2025-11-11 15:19:17 | 2025-11-11 07:34:33 |
| NVD | nvd_CVE-2017-12263 |
2025-11-11 14:55:32 | 2025-11-11 07:43:12 |
| CNNVD | cnnvd_CNNVD-201710-055 |
2025-11-11 15:09:54 | 2025-11-11 07:53:19 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 路径遍历
- cnnvd_id: 未提取 -> CNNVD-201710-055
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']