漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
Vulnerability Description
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
未经验证的口令修改
Vulnerability Title
OpenC3 COSMOS 安全漏洞
Vulnerability Description
OpenC3 COSMOS是OpenC3开源的一个应用程序。 OpenC3 COSMOS 6.10.5之前版本和7.0.0-rc3之前版本存在安全漏洞,该漏洞源于密码更改功能允许用户在不提供旧密码的情况下通过有效会话令牌更改密码,可能导致攻击者在已获取有效会话令牌的情况下劫持账户并阻止合法用户访问。
CVSS Information
N/A
Vulnerability Type
N/A