Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection. All instances have been patched by the Supplier.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
CWE-1336
Vulnerability Title
IPW Systems Metazo 安全漏洞
Vulnerability Description
IPW Systems Metazo是IPW Systems公司的一款工业物联网网关解决方案,实现现场设备与IT系统间的数据采集、处理和传输。 IPW Systems Metazo 8.1.3及之前版本存在安全漏洞,该漏洞源于smartyValidator.php允许提供模板表达式,可能导致服务器端模板注入。
CVSS Information
N/A
Vulnerability Type
N/A