漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Calero VeraSMART < 2022 R1 Static IIS Machine Keys Enable ViewState RCE
Vulnerability Description
Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\VeraSMART\\WebRoot\\web.config. An attacker who obtains these keys can craft a valid ASP.NET ViewState payload that passes integrity validation and is accepted by the application, resulting in server-side deserialization and remote code execution in the context of the IIS application.
CVSS Information
N/A
Vulnerability Type
使用硬编码的密码学密钥
Vulnerability Title
Calero VeraSMART 安全漏洞
Vulnerability Description
Calero VeraSMART是美国Calero公司的一个电话计费软件。 Calero VeraSMART 2022 R1之前版本存在安全漏洞,该漏洞源于使用静态的ASP.NET/IIS machineKey值,可能导致攻击者构造有效的ASP.NET ViewState有效载荷,进而导致服务器端反序列化和远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A