Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform at high risk because an authenticated user can retrieve all user account data and then retrieve the actual passwords.
CVSS Information
N/A
Vulnerability Type
使用未加Salt的单向哈希算法
Vulnerability Title
APM Classic 安全漏洞
Vulnerability Description
GE APM是美国通用电气(GE)公司的一款设备监控系统。该系统可以持续性对设备运行状态和故障进行监视。 APM Classic 4.4版本之前存在安全漏洞,该漏洞源于Salt不用于密码的散列计算,因此可以对密码进行解密。这种设计缺陷,加上IDOR漏洞,使整个平台处于高风险,攻击者可利用该漏洞通过身份验证的用户可以检索所有用户账户数据,然后再检索实际密码。
CVSS Information
N/A
Vulnerability Type
N/A