漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Credential Exposure Vulnerability in Trac PDBM
Vulnerability Description
The PDBM application relies on a static, hard‑coded secret embedded
in the PDBM.exe executable. This secret is used by the application’s
encryption routines, including the function responsible for decrypting
credentials stored in the product’s configuration file. Because the
secret is constant across installations, any attacker with sufficient
local privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored
password and authenticate as the user defined in the configuration file.
In the affected version, this user account is configured with
administrative privileges, granting full access to PDBM’s management
interface and its underlying operational functions.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
TRAC PDBM 安全漏洞
Vulnerability Description
TRAC PDBM是斯洛文尼亚TRAC公司的一个工业自动化流程数据库管理软件。 TRAC PDBM存在安全漏洞,该漏洞源于使用静态硬编码密钥,可能导致攻击者解密配置文件中存储的凭据并获取管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A