5.9.3 이전의 BC Security Empire는 remote code execution으로 이어질 수 있는 path traversal 문제에 취약합니다. 인증되지 않은 원격 공격자는 정상 agent처럼 동작하고 모든 cryptographic handshake를 완료한 다음, 악성 path가 포함된 payload data의 upload를 유발하여 HTTP를 통해 이 취약점을 악용할 수 있습니다.
5.9.3 이전의 BC Security Empire는 remote code execution으로 이어질 수 있는 path traversal 문제에 취약합니다. 인증되지 않은 원격 공격자는 정상 agent처럼 동작하고 모든 cryptographic handshake를 완료한 다음, 악성 path가 포함된 payload data의 upload를 유발하여 HTTP를 통해 이 취약점을 악용할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.