Cisco Secure Email Gateway に SQLインジェクションの脆弱性 すでに悪用も確認
予習
この記事のキーワード — タップで意味×7
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×3
悪用
あくよう
abuse; misuse; perversion
×1
悪意
あくい
1. ill will; spite; evil intention; malice 2. bad meaning
×1
細工
さいく
1. work; workmanship; craftsmanship; handiwork 2. artifice; trick; device; tampering; doctoring
N1×1
攻撃者
こうげきしゃ
aggressor; assailant; invader
一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は9月15日、Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性について発表した。影響を受けるシステムは以下の通り。
Cisco Secure Email Gateway向けCisco AsyncOSソフトウェア 16.5系の16.5.0-780より前のバージョン 16.0系の16.0.4-302より前のバージョン 15.5系以前の15.5.5-014より前のバージョン
Ciscoは9月15日に、Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)を公表している。本脆弱性の悪用により、認証されていないリモートの攻撃者が悪意のあるSQL文を含む細工したメールを送信し、脆弱性のある対象システムでメールを受け取ると、対象システム上でroot権限で任意のコマンドが実行される可能性がある。
Ciscoでは2026年9月に、本脆弱性の悪用を確認しており、JPCERT/CCでも同製品について、過去に別の脆弱性(CVE-2025-20393)を悪用した侵害事案の発生を確認している。
Ciscoでは、本脆弱性を修正したバージョンへのアップグレードを推奨している。
Cisco Secure Email Gateway向けCisco AsyncOSソフトウェア 16.5系の16.5.0-780より前のバージョン 16.0系の16.0.4-302より前のバージョン 15.5系以前の15.5.5-014より前のバージョン
Ciscoは9月15日に、Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)を公表している。本脆弱性の悪用により、認証されていないリモートの攻撃者が悪意のあるSQL文を含む細工したメールを送信し、脆弱性のある対象システムでメールを受け取ると、対象システム上でroot権限で任意のコマンドが実行される可能性がある。
Ciscoでは2026年9月に、本脆弱性の悪用を確認しており、JPCERT/CCでも同製品について、過去に別の脆弱性(CVE-2025-20393)を悪用した侵害事案の発生を確認している。
Ciscoでは、本脆弱性を修正したバージョンへのアップグレードを推奨している。
この記事の単語 (28)
×7
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×3
悪用
あくよう
abuse; misuse; perversion
×2
対象
たいしょう
target; object (of worship, study, etc.); subject (of taxation, etc.)
×2
確認
かくにん
confirmation; verification; validation; review; check; affirmation; identification
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
発表
はっぴょう
announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
×1
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×1
通り
とおり
1. avenue; street; way; road 2. coming and going; street traffic
×1
以前
いぜん
ago; since; before; previous
×1
公表
こうひょう
official announcement; proclamation
×1
認証
にんしょう
1. certification; attestation; authentication; confirmation 2. Imperial attestation
×1
攻撃者
こうげきしゃ
aggressor; assailant; invader
×1
悪意
あくい
1. ill will; spite; evil intention; malice 2. bad meaning
×1
含む
ふくむ
1. to contain; to comprise; to have; to hold; to include; to embrace 2. to hold in the mouth
×1
細工
さいく
1. work; workmanship; craftsmanship; handiwork 2. artifice; trick; device; tampering; doctoring
×1
送信
そうしん
transmission; sending
×1
受け取る
うけとる
1. to receive; to get; to accept 2. to take; to interpret; to understand
×1
権限
けんげん
power; authority; jurisdiction
×1
任意
にんい
1. optional; voluntary; arbitrary; random; discretionary; facultative; spontaneous; any 2. arbitrary
×1
実行
じっこう
execution (e.g. of a plan); carrying out; practice; action; implementation; fulfillment; realization
×1
可能性
かのうせい
potentiality; likelihood; possibility; availability
×1
製品
せいひん
manufactured goods; finished goods; product
×1
過去
かこ
1. the past; bygone days 2. one's past (that one would prefer remained secret)
×1
侵害
しんがい
infringement; violation; invasion; encroachment; trespass
×1
事案
じあん
concern; circumstance which is becoming a problem; case (court)
×1
発生
はっせい
1. outbreak; spring forth; occurrence; incidence 2. generation (e.g. of power or heat); genesis; origin
×1
修正
しゅうせい
amendment; correction; revision; modification; alteration; retouching; update; fix
×1
推奨
すいしょう
recommendation; endorsement