目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-5947 PoC — Deep Sea Electronics DSE855 安全漏洞

来源
关联漏洞
标题: Deep Sea Electronics DSE855 安全漏洞 (CVE-2024-5947)
Description:Deep Sea Electronics DSE855是英国Deep Sea Electronics公司的一个 USB 转以太网的通信设备。 Deep Sea Electronics DSE855 存在安全漏洞,该漏洞源于Web UI 中存在特定缺陷,允许访问功能缺乏身份验证,攻击者利用该漏洞可能泄露存储的凭据。
Description
Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-22679.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →