Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application stores the PBKDF2 derived key of users passwords with a low iteration count. An attacker with user profile access privilege can retrieve the stored password hashes of other accounts and then successfully perform an offline cracking attack and recover the plaintext passwords of other users.
CVSS Information
N/A
Vulnerability Type
使用具有不充分计算复杂性的口令哈希
Vulnerability Title
多款Siemens产品安全漏洞
Vulnerability Description
Siemens Desigo DXR2等都是德国西门子(Siemens)公司的一个楼宇自动化和控制产品。 Siemens Desigo DXR2 V01.21.142.5-22之前版本和Desigo PXC3 V01.21.142.4-18之前版本和Desigo PXC4 V02.20.142.10-10884之前版本和Desigo PXC5 V02.20.142.10-10884之前版本存在安全漏洞,该漏洞源于Web 应用程序以低迭代次数存储用户密码的 PBKDF2 派生密钥。具有用户配置文件访问权限的
CVSS Information
N/A
Vulnerability Type
N/A