CVE-2023-24243

CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
Configurations

Configuration 1 (hide)

cpe:2.3:a:cdata:arc:*:*:*:*:*:*:*:*

History

27 Jun 2023, 01:41

Type Values Removed Values Added
First Time Cdata
Cdata arc
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-918
CPE cpe:2.3:a:cdata:arc:*:*:*:*:*:*:*:*
References (MISC) https://www.cdata.com/kb/entries/netembeddedserver-notice.rst - (MISC) https://www.cdata.com/kb/entries/netembeddedserver-notice.rst - Vendor Advisory
References (MISC) https://gist.github.com/d3vc0r3/6460a5f006e32a2ebffe739e411ab1b8 - (MISC) https://gist.github.com/d3vc0r3/6460a5f006e32a2ebffe739e411ab1b8 - Exploit
References (MISC) https://arc.cdata.com/trial/ - (MISC) https://arc.cdata.com/trial/ - Product
References (MISC) https://arc.cdata.com/ - (MISC) https://arc.cdata.com/ - Product

16 Jun 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-16 17:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-24243

Mitre link : CVE-2023-24243

CVE.ORG link : CVE-2023-24243


JSON object : View

Products Affected

cdata

  • arc
CWE
CWE-918

Server-Side Request Forgery (SSRF)