| CNNVD-ID编号 | CNNVD-201905-1129 | CVE编号 | CVE-2019-10981 |
| 发布时间 | 2019-05-30 | 更新时间 | 2020-10-09 |
| 漏洞类型 | 信任管理问题 | 漏洞来源 | VAPT Team, C3i Center, and IIT Kanpur, and IIT Kanpur., and IIT Kanpur reported this vulnerability to AVEVA. |
| 危险等级 | 高危 | 威胁类型 | 本地 |
| 厂商 | N/A | ||
Schneider Electric AVEVA Vijeo Citect和Schneider Electric AVEVA CitectSCADA都是法国施耐德电气(Schneider Electric)公司的一套数据采集与监控系统(SCADA)软件。
Schneider Electric AVEVA Vijeo Citect和Schneider Electric AVEVA CitectSCADA中存在安全漏洞,该漏洞源于程序没有充分地保护凭证。本地攻击者可利用该漏洞访问Citect用户凭证。以下产品及版本受到影响:Schneider Electric AVEVA Vijeo Citect 7.30版本,7.40版本;Schneider Electric AVEVA CitectSCADA 7.30版本,7.40版本。
目前厂商已发布升级补丁以修复漏洞,详情请关注厂商主页:
https://www.aveva.com/
来源:BID
来源:CONFIRM
链接:https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityAdvisory_LFSec136.pdf
来源:www.aveva.com
来源:MISC
来源:BID
来源:ics-cert.us-cert.gov
来源:nvd.nist.gov
来源:www.securityfocus.com
来源:www.auscert.org.au
暂无