Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
密码学签名的验证不恰当
Vulnerability Title
Schneider Electric EcoStruxure Operator Terminal Expert 数据伪造问题漏洞
Vulnerability Description
Schneider Electric EcoStruxure Operator Terminal Expert是法国施耐德电气(Schneider Electric)公司的一款触控屏配置软件。该软件支主要用于创建和编辑触控应用程序。 Schneider Electric EcoStruxure Operator Terminal Expert V3.3 Hotfix 1及之前版本和Pro-face BLUE V3.3 Hotfix1及之前版本存在数据伪造问题漏洞,该漏洞源于加密签名验证不当,该漏洞允许具有
CVSS Information
N/A
Vulnerability Type
N/A