Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Trellix Enterprise Security Manager 安全漏洞
Vulnerability Description
Trellix Enterprise Security Manager(Trellix ESM)是美国火眼(Trellix)公司的一个应用程序。用于实时监控和分析使您能够快速确定隐藏威胁的优先级、调查和响应。 Trellix Enterprise Security Manager 11.6.10版本存在安全漏洞,该漏洞源于于对内部Snowservice API的未认证访问导致命令注入,可作为root用户执行远程代码。
CVSS Information
N/A
Vulnerability Type
N/A