漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Use of Hard-coded Credentials in SunPower PVS6
Vulnerability Description
The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. An attacker within Bluetooth range could exploit this vulnerability to gain full access to the device's servicing interface. This access allows the attacker to perform actions such as firmware replacement, disabling power production, modifying grid settings, creating SSH tunnels, altering firewall settings, and manipulating connected devices.
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
SunPower PVS6 信任管理问题漏洞
Vulnerability Description
SunPower PVS6是美国SunPower公司的一款太阳能光伏系统的数据监控与通信网关。 SunPower PVS6存在信任管理问题漏洞,该漏洞源于使用硬编码加密参数和公开协议细节,可能导致设备完全访问。
CVSS Information
N/A
Vulnerability Type
N/A