PT-2024-22030 · Sysaid · Sysaid

Niv Levy

·

Published

2024-03-28

·

Updated

2024-03-28

·

CVE-2024-27775

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SysAid versions prior to 23.2.14 b18
Description The issue allows for Server-Side Request Forgery (SSRF), which may expose the local OS user's NTLMv2 hash.
Recommendations For versions prior to 23.2.14 b18, update to version 23.2.14 b18 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-27775

Affected Products

Sysaid