HAVELSAN公司Liman渲染引擎中存在实体认证缺失的密钥交换漏洞,可能导致中间人攻击(AiTM)。 该问题影响版本范围:Liman渲染引擎1.0至1.2-75(不含1.2-75)。 --- 解析与关键术语说明: 1. 核心漏洞:密钥交换过程缺乏实体认证(如身份验证),导致攻击者可伪装成合法用户进行中间人攻击。 2. 攻击场景:Adversary in the Middle(AiTM)指攻击者拦截并篡改通信数据,窃听或操纵信息传输。 3. 影响版本:覆盖1.0到1.2-75的早期版本,需更新至后续版本以修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HAVELSAN Inc. | Liman Render Engine | 1.0< 1.2-75 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HAVELSAN Inc. | Liman Render Engine | 1.0 ~ 1.2-75 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77707 | 5.9 MEDIUM | TLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Liman Render En |
| CVE-2026-19532 | 5.3 MEDIUM | Path Traversal in HAVELSAN's Liman MYS |
No comments yet