CVE-2020-17386
Cellopoint CelloOS - Server-Side Request Forgery (SSRF)
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 1.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
25 Aug 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with the URL parameter and access arbitrary file on system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
Cellopoint · CelloOSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →