PT-2023-27137 · Unknown · Atx Ucrypt

Notnotnotveg

·

Publicado

2023-10-09

·

Atualizado

2024-02-01

·

CVE-2023-39854

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ATX Ucrypt versions 3.5 and earlier
Description The web interface of ATX Ucrypt allows authenticated users, or attackers using default credentials for the admin, master, or user account, to include files via a URL in the "/hydra/view/get cc url" url parameter. This can result in Server-Side Request Forgery (SSRF).
Recommendations For ATX Ucrypt versions 3.5 and earlier, consider disabling access to the "/hydra/view/get cc url" url parameter until a patch is available. Additionally, changing default credentials for the admin, master, and user accounts can help mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-39854

Produtos afetados

Atx Ucrypt