漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Phoenix Contact: Security Advisory for CHARX SEC-3xxx charging controllers
Vulnerability Description
An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resulting in a total loss of confidentiality, availability and integrity due to improper control of generation of code ('Code Injection').
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
Phoenix Contact CHARX SEC-3150 代码注入漏洞
Vulnerability Description
Phoenix Contact CHARX SEC-3150是德国菲尼克斯电气(Phoenix Contact)公司的一款交流充电控制器。 Phoenix Contact CHARX SEC-3150存在代码注入漏洞,该漏洞源于低权限远程攻击者可通过基于Web的管理账户更改系统配置执行命令注入,导致代码生成控制不当,可能完全丧失机密性、可用性和完整性。
CVSS Information
N/A
Vulnerability Type
N/A