漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Access to Bootloader
Vulnerability Description
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.
CVSS Information
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vulnerability Type
CWE-1191
Vulnerability Title
Autel MaxiCharger Single 权限许可和访问控制问题漏洞
Vulnerability Description
Autel MaxiCharger Single是美国Autel公司的一款电动汽车充电设备。 Autel MaxiCharger Single V1.03.51及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于暴露了可访问的UART接口,允许中断启动过程并访问U-Boot引导加载程序,具有物理访问权限的攻击者可修改启动配置或文件系统以获取操作系统访问权限。
CVSS Information
N/A
Vulnerability Type
N/A