Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Eclipse Milo 授权问题漏洞
Vulnerability Description
Eclipse Milo是美国Eclipse基金会开源的一个实现OPCUA协议的通信栈库。 Eclipse Milo 1.0.0版本至1.1.4版本存在授权问题漏洞,该漏洞源于Call服务在计算授权后将原始混合批次分派给地址空间处理程序,可能导致匿名或低权限客户端通过将拒绝的方法与允许的方法一起批处理来执行被禁止的方法。
CVSS Information
N/A
Vulnerability Type
N/A