脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
IP restriction bypass in Wertheim SafeController Software allows logins from unauthorized network locations
脆弱性説明
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability in the login process. The application restricts user logins based on the IP address associated with a branch location, but the client IP address is derived from the HTTP X-Forwarded-For header when that header is present. An attacker with valid branch user credentials can manipulate the X-Forwarded-For header during login to spoof the expected branch IP address and obtain a valid authenticated session from an unauthorized network location.
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
脆弱性タイプ
使用欺骗进行的认证绕过
脆弱性タイトル
Wertheim SafeController Software for VAULT ROOMS 授权问题漏洞
脆弱性説明
Wertheim SafeController Software for VAULT ROOMS是Wertheim公司的一款金库安全保险柜系统的控制软件。 Wertheim SafeController Software for VAULT ROOMS 6.15.8328.28014版本存在授权问题漏洞,该漏洞源于登录过程中存在IP限制绕过问题,当存在HTTP X-Forwarded-For标头时,客户端IP地址来自该标头,具有有效分支机构用户凭据的攻击者可以操作X-Forwarded-For标头来欺骗预
CVSS情報
N/A
脆弱性タイプ
N/A