漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
Vulnerability Description
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Microsoft UFO 授权问题漏洞
Vulnerability Description
Microsoft UFO是美国Microsoft公司的一款Web服务器。 Microsoft UFO 3.0.8之前版本存在授权问题漏洞,该漏洞源于ufo/client/mcp/http_servers/mobile_mcp_server.py中的create_mobile_data_collection_server和create_mobile_action_server在TCP端口8020和8021上暴露Streamable HTTP MCP服务且无需身份验证,可能导致未经身份验证的远程攻击者对AD
CVSS Information
N/A
Vulnerability Type
N/A