CVE-2022-39055

RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-6616-9092f-1.html Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:changingtec:rava_certificate_validation_system:3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-10-18 06:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-39055

Mitre link : CVE-2022-39055

CVE.ORG link : CVE-2022-39055


JSON object : View

Products Affected

changingtec

  • rava_certificate_validation_system
CWE
CWE-918

Server-Side Request Forgery (SSRF)