Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
RSA EnVision 3.5.0, 3.5.1, 3.5.2, and 3.7.0 does not properly restrict access to unspecified user profile functionality, which allows remote attackers to obtain the administrator password hash and conduct brute force guessing attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RSA enVision 平台Web控制台口令哈希泄露漏洞
Vulnerability Description
RSA EnVision是RSA Security产品家族中用于搜集和分析安全事件及日志的平台。 RSA EnVision平台提供了一个用于管理解决方案和分析安全事件的Web控制台,远程匿名攻击者可以利用这个控制台检索到用于认证的口令哈希。对这个哈希执行字典或暴力猜测攻击,攻击者就可以获得EnVision Web控制台的管理权限。
CVSS Information
N/A
Vulnerability Type
N/A