Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Schneider Electric 多款产品SESU更新欺骗漏洞
Vulnerability Description
施耐德电气为100多个国家的能源及基础设施、工业、数据中心及网络、楼宇和住宅市场提供整体解决方案。其中多个产品使用的SESU工具用于更新windows PC系统上的软件。客户PC上的Schneider Electric软件使用SESU服务作为Schneider Electric中心更新服务器的通信机制,可用于定期接收软件更新。 Schneider Electric Software Update (SESU) Utility 1.0.x和1.1.x版本中的客户端中存在漏洞,该漏洞源于确认更新有效的源。通过
CVSS Information
N/A
Vulnerability Type
N/A