Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
多款Honeywell产品 代码问题漏洞
Vulnerability Description
Honeywell software是美国霍尼韦尔(Honeywell)公司的一款应用软件。 多款Honeywell产品存在代码问题漏洞。远程攻击者可通过发送特制的请求利用该漏洞未经身份验证修改反序列化的数据,进而执行代码。以下产品及版本受到影响:HNMSWVMS VMS560 Build 595 T2-Patch之前版本,HNMSWVMSLT VMS560 Build 595 T2-Patch之前版本;MAXPRO NVR XE NVR 5.6 Build 595 T2-Patch之前版本,MAXPRO
CVSS Information
N/A
Vulnerability Type
N/A