Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
将资源暴露给错误范围
Vulnerability Title
Schneider Electric EcoStruxure Power Commission 安全漏洞
Vulnerability Description
Schneider Electric EcoStruxure Power Commission是法国施耐德电气(Schneider Electric)公司的一款综合性软件,可为低压配电柜的设置、测试和调试提供强大的功能。 EcoStruxure Power Commission 2.22之前版本存在安全漏洞。攻击者利用该漏洞可以访问所有服务器提供的资源(数据)。
CVSS Information
N/A
Vulnerability Type
N/A