漏洞标题
通过插件管理器认证任意Python文件上传漏洞
漏洞描述信息
经身份验证的攻击者可以利用Wattsense Bridge设备Web界面中的插件管理器上传恶意的Python文件到设备上。这使得攻击者能够获得对该设备的远程 root 访问权限。攻击者需要在Wattsense Web界面上拥有一个有效的用户账户才能实施此攻击。此问题已在最近的固件版本BSP >= 6.1.0中得到修复。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
危险类型文件的不加限制上传
漏洞标题
Authenticated Arbitrary Python File Upload via Plugin Manager
漏洞描述信息
An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device. This enables an attacker to gain remote root access to the device. An attacker needs a valid user account on the Wattsense web interface to be able to conduct this attack. This issue is fixed in recent firmware versions BSP >= 6.1.0.
CVSS信息
N/A
漏洞类别
危险类型文件的不加限制上传