ID

VAR-201209-0657


TITLE

Ezylog photovoltaic management server Session Management Vulnerability

Trust: 0.8

sources: IVD: 8d9d5c5c-1f56-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-5081

DESCRIPTION

Ezylog photovoltaic management server is a SCADA product. Ezylog photovoltaic management server's access to multiple pages (such as the \"ping.php\" script) failed to perform a proper authentication session check, and an attacker could exploit the vulnerability to gain unauthorized access to the administrative page

Trust: 0.72

sources: CNVD: CNVD-2012-5081 // IVD: 8d9d5c5c-1f56-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 8d9d5c5c-1f56-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-5081

AFFECTED PRODUCTS

vendor:schneidermodel:electric ezylog photovoltaic management serverscope: - version: -

Trust: 0.6

vendor:schneidermodel:electric ezylog photovoltaic management server nullscope:eqversion:*

Trust: 0.2

sources: IVD: 8d9d5c5c-1f56-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-5081

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 8d9d5c5c-1f56-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

IVD: 8d9d5c5c-1f56-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 8d9d5c5c-1f56-11e6-abef-000c29c66e3d

TYPE

Permission permission and access control

Trust: 0.2

sources: IVD: 8d9d5c5c-1f56-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:CNVDid:CNVD-2012-5081

Trust: 0.8

db:IVDid:8D9D5C5C-1F56-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 8d9d5c5c-1f56-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-5081

REFERENCES

url:http://seclists.org/bugtraq/2012/sep/44

Trust: 0.6

sources: CNVD: CNVD-2012-5081

SOURCES

db:IVDid:8d9d5c5c-1f56-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2012-5081

LAST UPDATE DATE

2022-05-17T01:43:30.274000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-5081date:2012-09-13T00:00:00

SOURCES RELEASE DATE

db:IVDid:8d9d5c5c-1f56-11e6-abef-000c29c66e3ddate:2012-09-13T00:00:00
db:CNVDid:CNVD-2012-5081date:2012-09-13T00:00:00