Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-4860

EPSS 1.63% · P82
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-4860

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
NOE 771设备ComputePassword函数信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NOE 771设备(也称为Quantum 140NOE771* 模块)上的Schneider Electric Quantum Ethernet 模块中的ComputePassword函数中存在漏洞,此函数通过执行MAC地址的计算产生fwupgrade账户密码。远程攻击者可借助(1) ARP 请求信息或者(2) Neighbor Solicitation信息获取访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-4860

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-4860

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-12-17 · 7 CVEs total

CVE-2011-4859Schneider Electric Quantum Ethernet模块安全漏洞
CVE-2011-4861NOE 771设备modbus_125_handler函数安全漏洞
CVE-2011-3339SafeNet Sentinel HASP/ 7T IGSS HTML注入漏洞
CVE-2011-4141RSA SecurID Software Token 任意代码执行漏洞
CVE-2011-4602Pidgin 多个拒绝服务漏洞
CVE-2011-4603Pidgin SILC协议拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-4860

No comments yet


Leave a comment