Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hvp-8gh4-hrx5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attackers to open a connection to the machine via the deviceIpAddr and connPort parameters.

A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attackers to open a connection to the machine via the deviceIpAddr and connPort parameters.

EPSS

Процентиль: 16%
0.00052
Низкий

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attackers to open a connection to the machine via the deviceIpAddr and connPort parameters.

EPSS

Процентиль: 16%
0.00052
Низкий

Дефекты

CWE-918