Control iD iDSecure 在 4.8.3.0 之前的版本受到未经身份验证的拒绝服务(Denial of Service)漏洞影响。 /api/license/restartService 端点可以在未经身份验证的情况下访问,并会调用一个内部例程,该例程通过生成的批处理脚本终止 iDSecure 服务进程并重新启动它。未经身份验证的远程攻击者可以反复调用此端点,使服务陷入持续的重启循环,从而导致其不可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Control iD | iDSecure | 0 ~ 4.8.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet