AJA HELO Plus 固件在 2.1.7 版本之前存在一个信息泄露漏洞,允许未经身份验证的攻击者利用固件中以混淆形式嵌入的静态 AES 口令来解密敏感的诊断数据包。攻击者可以通过逆向工程公开可用的固件镜像恢复该共享口令,并解密从任意受影响设备上未经身份验证的诊断端点获取的诊断导出包,从而暴露高度敏感的服务器信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AJA Video Systems | HELO Plus | 0 ~ 2.1.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet