漏洞描述 Johnson Controls CK721-A控制器固件SSM4388_03.1.0.14_BB之前版本中存在漏洞。远程攻击者可利用该漏洞通过传送到TCP 41014端口(又名下载端口)的特制数据包,执行任意操作。
相关漏洞推荐 POC gcloud-filestore-no-vpc-controls: Filestore Instance Not Protected by VPC Service Controls POC gcloud-vpc-service-controls-not-configured: Use VPC Service Controls for Cloud Storage Buckets POC download-unsigned-activex-allowed: Download of Unsigned ActiveX Controls Allowed Johnson Controls Software House C•CURE 9000 日志信息泄露漏洞 Delta Controls enteliTOUCH CVE-2022-29732 跨站脚本漏洞 Microsoft Windows Common Controls ActiveX控件远程代码执行漏洞(MS12-027)