Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ads-tec Industrial IT: Vertical privilege escalation via configuration table write
Vulnerability Description
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
授权机制缺失
Vulnerability Title
ads-tec Industrial IT DVG-IRF1401 授权问题漏洞
Vulnerability Description
ads-tec Industrial IT DVG-IRF1401是德国ads-tec Industrial IT公司的一款工业路由器。 ads-tec Industrial IT DVG-IRF1401、DVG-IRF1421、DVG-IRF3401、DVG-IRF3421、DVG-IRF3801和DVG-IRF3821 2.3.0之前版本存在授权问题漏洞,该漏洞源于配置表插入路径缺少授权,导致低权限远程攻击者可获得管理员权限,从而完全控制系统。
CVSS Information
N/A
Vulnerability Type
N/A