Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to trigger an unhandled exception, causing the server to return verbose .NET stack traces. These error messages expose internal class names, method calls, and third-party library references (e.g., System.Data.SQLite), which may assist attackers in mapping the application's internal structure.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
通过错误消息导致的信息暴露
Vulnerability Title
Navtor NavBox 安全漏洞
Vulnerability Description
Navtor NavBox是挪威Navtor公司的一款用于船舶电子海图管理和航行数据同步的航运信息系统设备。 Navtor NavBox存在安全漏洞,该漏洞源于/api/ais-data端点未处理异常,可能导致未经身份验证的远程攻击者获取内部应用程序结构信息。
CVSS Information
N/A
Vulnerability Type
N/A