PT-2022-12467 · Unknown · Shockwall System
宋侑霖
·
Published
2022-01-03
·
Updated
2022-01-07
·
CVE-2021-45917
CVSS v3.1
9.0
Critical
| Vector | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Shockwall system (affected versions not specified)
Description
The server-request receiver function of the system has an improper authentication issue. An authenticated attacker within the local area network can use local registry information to launch a server-side request forgery (SSRF) attack on another agent computer. This can result in arbitrary code execution, allowing the attacker to control the system or disrupt service.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shockwall System