Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mersive Solstice Pod 安全漏洞
Vulnerability Description
Mersive Solstice Pod是美国Mersive公司的一款应用于会议屏幕共享的软件。 Solstice Pod 3.3.0 (or Open4.3)之前版本存在安全漏洞,该漏洞源于可以通过配置服务initModel使用蛮力攻击枚举管理员密码。
CVSS Information
N/A
Vulnerability Type
N/A