Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropriate access control. (Furthermore, the user account that controls the web application service is granted full access to run any system commands with elevated privilege, without the need for password authentication. Should vulnerabilities be identified and exploited within the web application, it may be possible for a threat actor to create or run high-privileged binaries or executables that are available within the operating system of the device.)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多款ENTTEC产品访问控制错误漏洞
Vulnerability Description
ENTTEC Datagate MK2等都是澳大利亚ENTTEC公司的产品。ENTTEC Datagate MK2是一款照明控制器。ENTTEC Storm 24是一款以太网转DMX512转换器。ENTTEC Pixelator是一款像素控制器。 多款ENTTEC产品中存在访问控制错误漏洞。该漏洞源于网络系统或产品未正确限制来自未授权角色的资源访问。以下产品及版本受到影响:使用70044_update_05032019-482之前版本固件的ENTTEC Datagate MK2;使用70044_updat
CVSS Information
N/A
Vulnerability Type
N/A