漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Broken WebSocket authorization in Wertheim SafeController Software allows cross-branch access to restricted functions
Vulnerability Description
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communication used by the SafeController WebMessageBroker. An authenticated attacker with valid low-privileged branch user credentials can manipulate WebSocket messages by specifying controller identifiers belonging to other branches. This allows the attacker to access restricted functions and resources in other branches, including activating boxes outside of the user's authorized branch.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
Wertheim SafeController Software for VAULT ROOMS 授权问题漏洞
Vulnerability Description
Wertheim SafeController Software for VAULT ROOMS是Wertheim公司的一款金库安全保险柜系统的控制软件。 Wertheim SafeController Software for VAULT ROOMS 6.15.8328.28014版本存在授权问题漏洞,该漏洞源于WebSocket通信存在不正确的授权问题,可能导致经过身份验证的低权限用户通过指定其他分部的控制器标识符操纵WebSocket消息,从而访问受限功能和资源,包括激活授权分支之外的保险箱。
CVSS Information
N/A
Vulnerability Type
N/A