漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Rockwell Automation 1715 Redundant IO – Access Control Vulnerability
Vulnerability Description
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Rockwell Automation 1715 EtherNet/IP Communications Module 授权问题漏洞
Vulnerability Description
Rockwell Automation 1715 EtherNet/IP Communications Module是美国Rockwell Automation基金会的一款以太网通信网络模块。 1715 EtherNet/IP Communications Module 3.003及之前版本存在授权问题漏洞,该漏洞源于调试端口未强制执行适当的权限控制,允许未经身份验证的远程攻击者通过侵入性命令行界面访问,可能读取或删除文件、停止任务、修改内存以及更改I/O状态,影响设备的机密性、完整性和可用性。
CVSS Information
N/A
Vulnerability Type
N/A