漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). At 0x1e3f0 the extracted dns value from the xml file is used as an argument to /etc/config-tools/edit_dns_server %s dns-server-nr=%d dns-server-name=<contents of dns node> using sprintf(). This command is later executed via a call to system(). This is done in a loop and there is no limit to how many dns entries will be parsed from the xml file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WAGO PFC 200 操作系统命令注入漏洞
Vulnerability Description
WAGO PFC 200是德国WAGO公司的一款可编程逻辑控制器(PLC)。 WAGO PFC 200 03.02.02(14)版本中的iocheckd服务的I/O-Check功能存在操作系统命令注入漏洞。本地攻击者可通过发送特制的数据包利用该漏洞执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A