Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Schneider Electric EcoStruxure Operator Terminal Expert 路径遍历漏洞
Vulnerability Description
Schneider Electric EcoStruxure Operator Terminal Expert是法国施耐德电气(Schneider Electric)公司的一款触控屏配置软件。该软件支主要用于创建和编辑触控应用程序。 Schneider Electric EcoStruxure Operator Terminal Expert V3.3 Hotfix 1及之前版本和Pro-face BLUE V3.3 Hotfix1及之前版本存在路径遍历漏洞,该漏洞源于对受限目录路径名的不当限制,该漏洞允
CVSS Information
N/A
Vulnerability Type
N/A