Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-coded in an Inventory Agent configuration file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
COMPAREX Miss Marple Enterprise Edition 安全漏洞
Vulnerability Description
COMPAREX Miss Marple Enterprise Edition是德国COMPAREX公司的一套企业IT资产和许可证管理程序。 COMPAREX Miss Marple Enterprise Edition 2.0之前版本中存在安全漏洞,该漏洞源于程序使用了硬编码的AES密钥。本地攻击者可通过读取Inventory Agent配置文件中的硬编码加密密码利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A