PT-2020-17814 · Sysjust · Sysjust Syuan-Gu-Da-Shih
Published
2020-02-04
·
Updated
2022-05-24
·
CVE-2020-3938
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SysJust Syuan-Gu-Da-Shih versions before 20191223
Description
The issue allows attackers to launch inquiries into the network architecture or system files of the server via forged inquests, which is a type of Request Forgery. This enables attackers to potentially gain unauthorized access to sensitive information.
Recommendations
For versions before 20191223, update to a version released after 20191223 to resolve the issue. As a temporary workaround, consider restricting access to sensitive network architecture and system files to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sysjust Syuan-Gu-Da-Shih