PT-2025-20699 · Radware · Radware Cloud Web Application Firewall

Published

2025-05-08

·

Updated

2025-05-17

·

CVE-2024-56523

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Radware Cloud Web Application Firewall (WAF) versions prior to 2025-05-07
Description The issue allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method.
Recommendations For versions prior to 2025-05-07, update to a version released after 2025-05-07 to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources that could be exposed by this bypass.

Fix

Improper Access Control

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

BDU:2026-00298
CVE-2024-56523

Affected Products

Radware Cloud Web Application Firewall