PT-2022-12467 · Unknown · Shockwall System

宋侑霖

·

Published

2022-01-03

·

Updated

2022-01-07

·

CVE-2021-45917

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shockwall system (affected versions not specified)
Description The server-request receiver function of the system has an improper authentication issue. An authenticated attacker within the local area network can use local registry information to launch a server-side request forgery (SSRF) attack on another agent computer. This can result in arbitrary code execution, allowing the attacker to control the system or disrupt service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45917

Affected Products

Shockwall System