漏洞描述
Signal K Server versions up to and including 2.18.0 expose the /skServer/serialports, /skServer/availablePaths, and /skServer/hasAnalyzer endpoints without authentication. These routes were missing from the authentication middleware configuration, letting any unauthenticated user retrieve the full Signal K data schema, the list of connected serial devices, and whether traffic analyzer tools are installed. This template fingerprints the server via the public /signalk discovery endpoint and flags builds older than the fixed 2.19.0 release.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。