漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Missing authentication and clear‑text data transmission affecting Orca heat pumps
Vulnerability Description
Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca server over an
unencrypted and unauthenticated HTTP connection on a non-secure port specifically enable an
attacker to impersonate a legitimate device and inject malicious
payloads. This enables the insertion of harmful code directly
into the Orca user portal, potentially compromising user accounts,
exposing sensitive information, and allowing further unauthorized
actions within the portal.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Orca Energija Orca heat pump 安全漏洞
Vulnerability Description
Orca Energija Orca heat pump是Orca Energija公司的一系列空气‑水热泵系统。 Orca Energija Orca heat pump存在安全漏洞,该漏洞源于缺少身份验证和明文传输数据,结合聚合数据输入验证缺失,可能导致存储型跨站脚本攻击,从而窃取泵Web控制界面的cookie。
CVSS Information
N/A
Vulnerability Type
N/A