Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVE-2023-22804
Vulnerability Description
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
LS ELECTRIC XBC-DN32U 访问控制错误漏洞
Vulnerability Description
LS ELECTRIC XBC-DN32U是韩国LS ELECTRIC公司的一款 PLC 可编程逻辑控制器。 LS ELECTRIC XBC-DN32U 01.80版本存在访问控制错误漏洞,该漏洞源于缺少对 PLC 创建用户的身份验证,攻击者利用该漏洞可以创建和使用具有提升权限的帐户,并控制设备。
CVSS Information
N/A
Vulnerability Type
N/A