Request Smuggling Consente agli Attaccanti di Prendere il Controllo dei Data Manager Siemens
Una falla nel confine delle web request nel SENTRON 7KT PAC1261 Data Manager può superare i normali controlli di accesso del dispositivo. Se il web server è esposto, un attaccante può rubare token di autorizzazione e usarli per ottenere il controllo amministrativo, quindi non si tratta solo di un fastidioso bug di parsing.
CVSS 9.1 CRITICAL: the net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. EPSS 0.8% (55º percentile).
Siemens SENTRON 7KT PAC1261 Data Manager Summary The web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to retrieve authorization tokens that can be used to gain…