Record summary

CVE-2022-41412 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 17, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 24, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHperfSONAR 4.x <= 4.4.4 - Server-Side Request ForgeryCVSS 8.6

An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.

Impact

Unauthenticated attackers can exploit SSRF vulnerabilities in the graphData.cgi component to access internal resources, bypass firewall restrictions, and potentially access sensitive performance measurement data from internal network monitoring systems.

Remediation

Upgrade to perfSONAR version 4.4.5 or later that validates and restricts URL parameters in the graphData.cgi component.

WeaknessesCWE-918
Authorsnull_hypothesis
Template tagscvecve2022ssrfhackeronepacketstormperfsonarvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CPE: cpe:2.3:a:perfsonar:perfsonar:*:*:*:*:*:*:*:*
FOFA: title="perfSONAR Toolkit"
FOFA: title="perfsonar toolkit"

Source: ProjectDiscovery

References

3