PT-2020-9554 · Adrem · Adrem Netcrunch

Published

2020-12-16

·

Updated

2020-12-18

·

CVE-2019-14476

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: AdRem NetCrunch version 10.6.0.4587
Description: The issue allows every user to trick the server into performing SMB requests to other systems due to a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server.
Recommendations: For AdRem NetCrunch version 10.6.0.4587, consider restricting access to the NetCrunch server to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the ability of the server to perform SMB requests to other systems. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14476

Affected Products

Adrem Netcrunch