Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escalated privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
fs.com S3900-24T4S 跨站请求伪造漏洞
Vulnerability Description
fs.com S3900-24T4S是中国飞速创新(fs)公司的一款千兆可堆叠式交换机。FS S3900-24T4S交换机配备24个10/100/1000Base-T端口,4个10G SFP+上行链路口,支持高达6台交换机堆叠,操作简便,具备高度安全的业务处理能力、灵活的网络部署、无边界的网络体验和完备的QoS控制策略。 fs.com S3900 24T4S 1.7.0版本及之前版本存在安全漏洞,攻击者可利用该漏洞代表站点管理员伪造更改所有设置(包括删除用户、创建具有升级特权的新用户)的身份验证或令牌身份
CVSS Information
N/A
Vulnerability Type
N/A