PT-2020-17814 · Sysjust · Sysjust Syuan-Gu-Da-Shih

Published

2020-02-04

·

Updated

2022-05-24

·

CVE-2020-3938

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SysJust Syuan-Gu-Da-Shih versions before 20191223
Description The issue allows attackers to launch inquiries into the network architecture or system files of the server via forged inquests, which is a type of Request Forgery. This enables attackers to potentially gain unauthorized access to sensitive information.
Recommendations For versions before 20191223, update to a version released after 20191223 to resolve the issue. As a temporary workaround, consider restricting access to sensitive network architecture and system files to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-3938

Affected Products

Sysjust Syuan-Gu-Da-Shih