Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
EnOcean SmartServer IoT Command Injection
Vulnerability Description
A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
EnOcean SmartServer IoT 命令注入漏洞
Vulnerability Description
EnOcean SmartServer IoT是德国EnOcean公司的一款多协议IoT边缘服务器。 EnOcean SmartServer IoT 4.60.009及之前版本存在命令注入漏洞,该漏洞源于处理特制的IP-852消息不当,可能导致远程攻击者执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A