漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Certificate Validation in CODESYS Git
Vulnerability Description
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server provides a valid and trusted HTTPS certificate. Since the certificate of the server to which the connection is made is not properly verified, the server connection is vulnerable to a man-in-the-middle attack.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
证书验证不恰当
Vulnerability Title
CODESYS 信任管理问题漏洞
Vulnerability Description
CODESYS是德国3S-Smart Software Solutions的一套控制器开发系统 CODESYS Git 存在信任管理问题漏洞,该漏洞源于受影响的CODESYS Git版本在V1.1.0.0之前的版本中缺少HTTPS握手中的证书验证。攻击者可利用该漏洞导致中间人攻击。
CVSS Information
N/A
Vulnerability Type
N/A