Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper authorization in device bulk actions and device update API allows cross-organization device control
Vulnerability Description
Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update API. Missing authorization checks in the device bulk actions and device update API endpoints allow authenticated users to target devices belonging to other organizations and perform actions outside of their privilege level. An attacker can select devices outside of their organization by manipulating device identifiers and perform management actions on them, such as moving them to products they control. This may allow attackers to interfere with firmware updates, access device functionality exposed by the platform, or disrupt device connectivity. In environments where additional features such as remote console access are enabled, this could lead to full compromise of affected devices. This issue affects nerves_hub_web: from 1.0.0 before 2.4.0.
CVSS Information
N/A
Vulnerability Type
授权机制不恰当
Vulnerability Title
NervesHub 安全漏洞
Vulnerability Description
NervesHub是NervesHub开源的一个管理Nerves设备的固件更新的软件。 NervesHub 1.0.0版本至2.4.0之前版本存在安全漏洞,该漏洞源于设备批量操作和设备更新API缺少授权检查,可能导致跨组织设备控制。
CVSS Information
N/A
Vulnerability Type
N/A