漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Circutor COMPACT DC-S BASIC
Vulnerability Description
A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in this web portal, a potential attacker could submit any "Address" value and it would be copied to a second variable with a "strcpy" vulnerable function without checking its length. Because of this, it is possible to send a long address value to overflow the process stack, controlling the function return address.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
栈缓冲区溢出
Vulnerability Title
Circutor COMPACT DC-S BASIC 安全漏洞
Vulnerability Description
Circutor COMPACT DC-S BASIC是西班牙Circutor公司的一款紧凑型直流集中器。 Circutor COMPACT DC-S BASIC CIR_CDC_v1.2.17 版本存在安全漏洞,该漏洞源于备管理门户的防火墙功能中存在缓冲区溢出。攻击者可以发送长地址值来利用该漏洞控制函数返回地址。
CVSS Information
N/A
Vulnerability Type
N/A