漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.
CVSS Information
N/A
Vulnerability Type
未经引用的搜索路径或元素
Vulnerability Title
Schneider Electric EcoStruxure Building Operation Enterprise Server 代码问题漏洞
Vulnerability Description
施耐德电气 Schneider Electric EcoStruxure Building Operation Enterprise Server是法国施耐德电气公司的一个企业级楼宇控制系统。该系统以计算机网络为基础、软件为核心,结合智能建筑的工程建设的经验将楼宇中各个具有完整功能的独立分系统组合成一个有机的整体。 Schneider Electric EcoStruxure Building Operation Enterprise Server installer 1.9版本至3.1版本和 Enter
CVSS Information
N/A
Vulnerability Type
N/A