Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry. Affected Product: Schneider Electric Software Update, V2.3.0 through V2.5.1
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Schneider Electric Software Update 安全特征问题漏洞
Vulnerability Description
Schneider Electric Software Update是法国施耐德电气(Schneider Electric)公司的一款用于Schneider Electric产品的软件更新工具。 Schneider Electric Software Update (SESU) 存在安全特征问题漏洞,该漏洞源于 Schneider Electric Software Update (SESU) 存在熵不足漏洞,当攻击者设法从注册表解密SESU代理密码时,该漏洞可能导致内部网络意外连接到外部网络。
CVSS Information
N/A
Vulnerability Type
N/A