PT-2022-24700 · Unknown · Rava Certificate Validation System

Jay Wu

+1

·

Published

2022-10-18

·

Updated

2022-10-20

·

CVE-2022-39055

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions RAVA certificate validation system (affected versions not specified)
Description The RAVA certificate validation system has inadequate filtering for the URL parameter, allowing an unauthenticated remote attacker to perform a Server-Side Request Forgery (SSRF) attack. This can enable the attacker to discover the internal network topology based on the query response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-39055

Affected Products

Rava Certificate Validation System