PT-2024-17139 · Ipc · Ipc Unigy Management System

Braga

·

Published

2024-11-22

·

Updated

2024-11-22

·

CVE-2024-11618

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IPC Unigy Management System version 04.03.00.08.0027
Description A critical issue was found in the HTTP Request Handler component, which can lead to server-side request forgery. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations For IPC Unigy Management System version 04.03.00.08.0027, consider restricting access to the HTTP Request Handler component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-11618

Affected Products

Ipc Unigy Management System