Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certificate pinning during the TLS/SSL connection establishing process can result in a man-in-the-middle attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Schneider Electric IGSS Mobile 安全漏洞
Vulnerability Description
Schneider Electric IGSS Mobile是法国施耐德电气(Schneider Electric)公司的一套用于管理IGSS(共享服务平台)的移动端应用程序。 Schneider Electric IGSS Mobile 3.01及之前版本中存在安全漏洞,该漏洞源于在TLS/SSL连接建立过程中缺少证书锁定。攻击者可利用该漏洞实施中间人攻击。
CVSS Information
N/A
Vulnerability Type
N/A