漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app
Vulnerability Description
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server. The traffic is weakly encrypted using RC4 with a hardcoded key, which allows an attacker to gain access to the communication. Part of this communication involves access codes to charging stations. This issue affects EVbee Service: v1.4.101.00.
CVSS Information
N/A
Vulnerability Type
证书验证不恰当
Vulnerability Title
EVbee Service 加密问题漏洞
Vulnerability Description
EVbee EVbee Service是EVbee公司的一款电动汽车充电服务管理软件。 EVbee Service 1.4.101.00版本存在加密问题漏洞,该漏洞源于未验证服务器提供的证书且使用弱加密,可能导致网络路径中的攻击者拦截和操纵应用与服务器之间的通信。
CVSS Information
N/A
Vulnerability Type
N/A