在 EFM ipTIME T24000M 设备的 14.20.0 及更早版本中检测到一个安全漏洞。该漏洞影响会话验证处理器(Session Validation Handler)组件中的 函数。此类操纵会导致身份验证机制失效,从而引发不正确的身份验证行为。该漏洞可由远程攻击者利用,且相关漏洞利用代码已被公开披露,可能存在被实际使用的风险。厂商在漏洞公开初期已收到通知,但至今未作出任何回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| EFM | ipTIME T24000M | 14.0 |
affected |
14.1 |
affected | ||
14.2 |
affected | ||
14.3 |
affected | ||
14.4 |
affected | ||
14.5 |
affected | ||
14.6 |
affected | ||
14.7 |
affected | ||
| … +13 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EFM | ipTIME T24000M | 14.0 |
cpe:2.3:a:efm:iptime_t24000m:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet