Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NASA AIT-Core 安全漏洞
Vulnerability Description
NASA AIT-Core是美国NASA组织的一个基于 Python 的软件套件。 NASA AIT-Core 2.5.2版本存在安全漏洞,该漏洞源于使用未加密通道在网络上交换数据,攻击者能够执行中间人攻击。
CVSS Information
N/A
Vulnerability Type
N/A