目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2023-27336— Softing edgeConnector 安全漏洞

AI Predicted 7.5 Difficulty: Easy EPSS 0.81% · P54
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2023-27336の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability
ソース: CVE Program / CVE List V5
脆弱性説明
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OPC client certificates. The issue results from dereferencing a NULL pointer. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20508.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
空指针解引用
ソース: CVE Program / CVE List V5
脆弱性タイトル
Softing edgeConnector 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Softing edgeConnector是Softing公司的一款基于 Docker 的软件应用。可访问 SIMATIC S7、SINUMERIK 840D 和 Modbus TCP 控制器中的过程数据。 Softing edgeAggregator 存在安全漏洞,该漏洞源于OPC 客户端证书的处理中存在取消引用空指针,攻击者利用该漏洞可以在系统上创建拒绝服务条件。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
SoftingedgeConnector Siemens 3.40 -

II. CVE-2023-27336の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2023-27336のインテリジェンス情報

登录查看更多情报信息。

CVE-2023-27336 厂商安全公告 (1)

Same Patch Batch · Softing · 2024-05-03 · 9 CVEs total

CVE-2023-39480Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vuln
CVE-2023-39481Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerabil
CVE-2023-39482Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulne
CVE-2023-39479Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability
CVE-2023-39478Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Executi
CVE-2023-38125Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code E
CVE-2023-27334Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulne
CVE-2023-27335Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability

IV. 関連脆弱性

V. CVE-2023-27336へのコメント

まだコメントはありません


コメントを残す