漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Metasys Improper Privilege Management
Vulnerability Description
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
Johnson Controls Metasys 安全漏洞
Vulnerability Description
Johnson Controls Metasys system是美国江森自控(Johnson Controls)公司的一套楼宇自动化系统。 Johnson Controls Metasys 11.0版本及之前版本存在安全漏洞,该漏洞允许攻击者向Metasys系统发送专门设计的web消息来访问或修改系统文件。
CVSS Information
N/A
Vulnerability Type
N/A