PT-2021-23285 · Securonix · Securonix Snypr

Published

2021-09-27

·

Updated

2021-10-05

·

CVE-2021-41385

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Securonix SNYPR version 6.3.1 Build 184295 0302
Description The issue allows an authenticated user to obtain access to server configuration details via Server-Side Request Forgery (SSRF) in the third party intelligence connector.
Recommendations For Securonix SNYPR version 6.3.1 Build 184295 0302, consider restricting access to the third party intelligence connector to minimize the risk of exploitation until a patch is available.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41385

Affected Products

Securonix Snypr