Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. Specifically, /cgi/loginDefaultUser creates a session in an authenticated state and returns the session ID along with what may be the username and cleartext password of the user. An attacker can then supply an IDALToken value in a cookie, which will allow them to perform privileged operations such as restarting the service with /cgi/restart. A GET request to /cgi/loginDefaultUser may result in "1 #S_OK IDALToken=532c8632b86694f0232a68a0897a145c admin admin" or a similar response.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ABB PB610 Panel Builder 600 授权问题漏洞
Vulnerability Description
ABB PB610 Panel Builder 600是瑞士ABB公司的一款为CP600控制面板平台设计图形用户界面的软件。 使用1.91版本至2.8.0.367版本固件的ABB PB610 Panel Builder 600的IDAL CGI接口存在安全漏洞。攻击者可利用该漏洞绕过身份验证并获取被限制功能的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A