emerson-intellislot-webcard: Emerson Network Power IntelliSlot Web Card - Exposure

日期: 2025-08-01 | 影响软件: Emerson Intellislot Webcard | POC: 已公开

漏洞描述

Emerson IntelliSlot Web Card interface panel was discovered. This web interface provides remote monitoring and management capabilities for Emerson Network Power devices. Unauthorized access to this interface could potentially allow attackers to view sensitive information or control critical infrastructure equipment. Proper authentication and access controls should be implemented to secure this interface.

PoC代码[已公开]

id: emerson-intellislot-webcard

info:
  name: Emerson Network Power IntelliSlot Web Card - Exposure
  author: Th3l0newolf
  severity: medium
  description: |
    Emerson IntelliSlot Web Card interface panel was discovered. This web interface provides remote monitoring and management capabilities for Emerson Network Power devices. Unauthorized access to this interface could potentially allow attackers to view sensitive information or control critical infrastructure equipment. Proper authentication and access controls should be implemented to secure this interface.
  reference:
    - https://www.vertiv.com
  metadata:
    verified: true
    max-request: 1
    shodan-query: 'http.title:"Emerson Network Power IntelliSlot Web Card"'
  tags: emerson,intellislot,iot,misconfig,exposure,discovery

http:
  - method: GET
    path:
      - "{{BaseURL}}"

    host-redirects: true
    max-redirects: 2

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "<title>Emerson Network Power IntelliSlot Web Card</title>"

      - type: status
        status:
          - 200
# digest: 490a0046304402204ff52a12bfc87d5a6413359fc55821da29dc041eab2092dd4ce969845883f90d02204dedfdb41134965e7d42b5d9f13616d58380d9fa9153586c3b01114cba67ad75:922c64590222798bb761d5b6d8e72950