漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
IP restriction bypass in Wertheim SafeController Software allows logins from unauthorized network locations
Vulnerability Description
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability in the login process. The application restricts user logins based on the IP address associated with a branch location, but the client IP address is derived from the HTTP X-Forwarded-For header when that header is present. An attacker with valid branch user credentials can manipulate the X-Forwarded-For header during login to spoof the expected branch IP address and obtain a valid authenticated session from an unauthorized network location.
CVSS Information
N/A
Vulnerability Type
使用欺骗进行的认证绕过
Vulnerability Title
Wertheim SafeController Software for VAULT ROOMS 授权问题漏洞
Vulnerability Description
Wertheim SafeController Software for VAULT ROOMS是Wertheim公司的一款金库安全保险柜系统的控制软件。 Wertheim SafeController Software for VAULT ROOMS 6.15.8328.28014版本存在授权问题漏洞,该漏洞源于登录过程中存在IP限制绕过问题,当存在HTTP X-Forwarded-For标头时,客户端IP地址来自该标头,具有有效分支机构用户凭据的攻击者可以操作X-Forwarded-For标头来欺骗预
CVSS Information
N/A
Vulnerability Type
N/A