漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO
Vulnerability Description
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service command. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enforcement and a wildcard CORS policy, then emit the service_control event to terminate all active satellite-tracking sessions, SDR recording pipelines, demodulators, decoders, and rotator controllers, with repeated triggering possible in Docker deployments to create a persistent denial-of-service condition.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Efstratios Goudelis Ground Station 授权问题漏洞
Vulnerability Description
Efstratios Goudelis Ground Station是Efstratios Goudelis公司的一款卫星通信地面站设备。 Efstratios Goudelis Ground Station 0.6.0之前版本存在授权问题漏洞,该漏洞源于Socket.IO服务器service_control事件处理器存在认证缺失,允许未经身份验证的攻击者通过发送restart_service命令终止进程,导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A