Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ESPEC North America Web Controller 3 安全漏洞
Vulnerability Description
ESPEC North America Web Controller 3是美国ESPEC North America公司的一个实验室设备监控软件。 ESPEC North America Web Controller 3 3.3.4之前版本存在安全漏洞,该漏洞源于无效认证请求导致JWT密钥泄露,可能导致UI权限提升。
CVSS Information
N/A
Vulnerability Type
N/A