Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
Schneider Electric EcoStruxure Power Monitoring Expert 代码问题漏洞
Vulnerability Description
Schneider Electric EcoStruxure Power Monitoring Expert是法国施耐德电气(Schneider Electric)公司的一个用于物联网环境中进行配电监控的设备。 Schneider Electric EcoStruxure Power Monitoring Expert存在代码问题漏洞,该漏洞源于存在会话过期不足漏洞,攻击者利用该漏洞可能保持对被劫持会话的未授权访问。
CVSS Information
N/A
Vulnerability Type
N/A