CVE-2021-33221: CommScope Ruckus IoT Controller – Information Disclosure

CVE-2021-33221: CommScope Ruckus IoT Controller - Information Disclosure-渗透云记 - 专注于网络安全与技术分享
CVE-2021-33221: CommScope Ruckus IoT Controller – Information Disclosure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-33221: CommScope Ruckus IoT Controller – Information Disclosure

漏洞描述

CommScope Ruckus IoT Controller is susceptible to information disclosure vulnerabilities because a 'service details' API endpoint discloses system and configuration information to an attacker without requiring authentication. This information includes DNS and NTP servers that the devices use for time and host resolution. It also includes the internal hostname and IoT Controller version. A fully configured device in production may leak other, more sensitive information (API keys and tokens).

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享