CVE-2022-39055

MEDIUM

RAVA Certificate Validation System - URL Parameter Server-Side Request Forgery

Title source: manual
STIX 2.1

Description

RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0041
EPSS Percentile 32.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
changingtec/rava_certificate_validation_system 3
Published Oct 18, 2022
Tracked Since Feb 18, 2026