KevinLAB Building Energy Management System(KevinLAB BEMS)是韩国KevinLAB公司的一个建筑能源管理系统。 KevinLAB Building Energy Management System 1.0.0 中存在安全漏洞,攻击者可以使用具有管理员最高权限的后台帐户登录并获得系统控制权。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | KevinLAB BEMS has an undocumented backdoor account, and these sets of credentials are never exposed to the end-user and cannot be changed through any normal operation of the solution through the RMI. An attacker could exploit this vulnerability by logging in using the backdoor account with highest privileges for administration and gain full system control. The backdoor user cannot be seen in the users settings in the admin panel, and it also uses an undocumented privilege level (admin_pk=1) which allows full availability of the features that the BEMS is offering remotely. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37292.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2021-32162 | Webmin 跨站请求伪造漏洞 | |
| CVE-2021-37291 | KevinLAB Building Energy Management System SQL注入漏洞 | |
| CVE-2021-40219 | Bolt CMS 代码注入漏洞 | |
| CVE-2022-27111 | Jfinal CMS跨站脚本漏洞 | |
| CVE-2022-27156 | Daylight Studio Fuel CMS跨站脚本漏洞 | |
| CVE-2022-27115 | elFinder 代码问题漏洞 | |
| CVE-2022-27088 | Ivanti DSM Remote 及 代码问题漏洞 | |
| CVE-2022-27089 | Fujitsu PlugFree Network 代码问题漏洞 | |
| CVE-2022-27041 | openSIS SQL注入漏洞 | |
| CVE-2021-37293 | KevinLAB Building Energy Management System 路径遍历漏洞 | |
| CVE-2021-32161 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32160 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32159 | Webmin 跨站请求伪造漏洞 | |
| CVE-2021-32158 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32157 | Webmin 跨站脚本漏洞 | |
| CVE-2021-32156 | Webmin 跨站请求伪造漏洞 | |
| CVE-2022-28893 | Linux kernel 资源管理错误漏洞 | |
| CVE-2022-25794 | Autodesk FBX Review 缓冲区错误漏洞 | |
| CVE-2022-25790 | Autodesk AutoCAD 缓冲区错误漏洞 | |
| CVE-2021-4047 | Red Hat OpenShift 输入验证错误漏洞 |
显示前 20 条,共 37 条。 查看全部 → →
暂无评论