漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Violation of Least Privilege Principle
Vulnerability Description
The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running "ps aux" as the root user and observing the output.
CVSS Information
N/A
Vulnerability Type
带着不必要的权限执行
Vulnerability Title
Image Access Scan2Net 安全漏洞
Vulnerability Description
Image Access Scan2Net是德国Image Access公司的一款扫描软件。 Image Access Scan2Net存在安全漏洞,该漏洞源于扫描仪设备默认启动到kiosk模式,并在浏览器窗口中打开Scan2Net界面。此时浏览器以root权限运行。
CVSS Information
N/A
Vulnerability Type
N/A