← volver
CVE-2024-1965

Server-Side Request Forgery Vulnerability in Haivision Products

CVSS 6.5 MEDIUMEPSS 0.4%CWE-918
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
28 feb 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need for credentials. An attacker could compromise an internal server and retrieve requests sent by other users.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N