漏洞标题
N/A
漏洞描述信息
在130.8005 TCP/IP网关运行固件版本12h时,发现存在CWE-126“缓冲区读取溢出”漏洞。该漏洞可通过利用影响Web服务器的内存泄漏来触发信息泄露。远程未认证攻击者可利用此漏洞从与当前登录系统用户关联的进程内存中泄露有效的认证令牌,从而绕过认证机制。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
跨界内存读
漏洞标题
N/A
漏洞描述信息
A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The information disclosure can be triggered by leveraging a memory leak affecting the web server. A remote unauthenticated attacker can exploit this vulnerability in order to leak valid authentication tokens from the process memory associated to users currently logged to the system and bypass the authentication mechanism.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
漏洞类别
缓冲区上溢读取