AiSOC 7.2.0 至 12.0.0(不含 12.0.0)版本中存在命令注入漏洞。该漏洞位于 CrowdStrike Real Time Response 的命令构建服务中,具体出现在 crowdstrike_rtr.py 和 endpoint.py 文件里。这些模块通过插值方式将未经验证或转义的操作参数嵌入到命令字符串中。攻击者在已认证的情况下,可以向 file_path、path、script_name 或 script_args 参数中注入单引号,从而跳出原有引号包裹的参数结构,最终在受管终端上以 SYS
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103055 | 7.5 HIGH | AiSOC 7.5.0 before 12.0.0 Authentication Bypass via Hard-coded JWT Secret |
| CVE-2026-103054 | 7.1 HIGH | AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP |
| CVE-2026-103053 | 5.4 MEDIUM | AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API |
| CVE-2026-103057 | 4.3 MEDIUM | AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal Endpoints |
No comments yet