Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An attacker who successfully exploited these vulnerabilities could grant read access to files. A vulnerability exists in the AC500 V3 version mentioned. A successfully authenticated attacker can use this vulnerability to read system wide files and configuration All AC500 V3 products (PM5xxx) with firmware version earlier than 3.8.0 are affected by this vulnerability.
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
ABB AC500 路径遍历漏洞
Vulnerability Description
ABB AC500是瑞士ABB公司的一款可编程逻辑控制器 PLC。 ABB AC500 V3 3.8.0之前版本存在路径遍历漏洞,该漏洞源于权限检查不当,认证后的攻击者可读取系统范围的文件和配置。
CVSS Information
N/A
Vulnerability Type
N/A