漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Session Management Vulnerability in Tacitine Firewall
Vulnerability Description
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to perform session fixation on the targeted device.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
会话固定
Vulnerability Title
Tacitine EN6200 授权问题漏洞
Vulnerability Description
Tacitine EN6200是Tacitine公司的一系列防火墙。 Tacitine Firewall 的 EN6200-PRIME QUAD-35和EN6200-PURIME QUAD-100 19.1.1版本至22.20.1版本存在安全漏洞,该漏洞源于Tacitine-Firewall基于web的管理界面中的会话管理不当。
CVSS Information
N/A
Vulnerability Type
N/A