漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Hard-coded credentials in KS-SOMED
Vulnerability Description
Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update.
This issue affects KS-SOMED with modules: KSPLUPDFTP.exe up to 30.00.00.056 and ANEKSKLIENT.EXE up to 29.00.02.026
Beside removing the hard-coded credentials from the code and changing the update process, access granted by previously exposed credentials was limited to read-only.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
KAMSOFT KS-SOMED 信任管理问题漏洞
Vulnerability Description
KAMSOFT KS-SOMED是波兰KAMSOFT公司的一个医疗机构综合管理系统。 KAMSOFT KS-SOMED存在信任管理问题漏洞,该漏洞源于使用硬编码凭据,可能导致未经授权的攻击者访问托管应用程序更新包的FTP服务器,上传恶意更新文件并分发安装到客户端机器。以下版本受到影响:KSPLUPDFTP.exe 30.00.00.056及之前版本和ANEKSKLIENT.EXE 29.00.02.026及之前版本。
CVSS Information
N/A
Vulnerability Type
N/A