Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system status. Fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Solar-Log 访问控制错误漏洞
Vulnerability Description
Solar-Log GmbH Solar-Log是德国Solar-Log GmbH公司的一个用于监控光伏电站的数据记录器。 Solar-Log 存在安全漏洞,该漏洞源于在2.8.2 Build 52之前的Solar-Log 500中的web管理服务器不需要身份验证,这允许远程攻击者可利用该漏洞通过连接到服务器来获得管理权限。这样,攻击者可利用该漏洞就可以修改配置文件,改变系统状态。
CVSS Information
N/A
Vulnerability Type
N/A