PT-2022-24700 · Unknown · Rava Certificate Validation System

·

CVE-2022-39055

·

Published

2022-10-18

·

Updated

2022-10-20

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions RAVA certificate validation system (affected versions not specified)
Description The RAVA certificate validation system has inadequate filtering for the URL parameter, allowing an unauthenticated remote attacker to perform a Server-Side Request Forgery (SSRF) attack. This can enable the attacker to discover the internal network topology based on the query response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39055

Affected Products

Rava Certificate Validation System