Record summary

CVE-2023-24243 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHCData RSB Connect v22.0.8336 - Server Side Request ForgeryCVSS 7.5

CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).

Impact

Successful exploitation of this vulnerability could allow an attacker to send arbitrary requests from the server, potentially leading to unauthorized access or data leakage.

Remediation

Apply the latest security patches or updates provided by CData to fix the SSRF vulnerability in RSB Connect v22.0.8336.

WeaknessesCWE-918
Authorsritikchaddha
Template tagscvecve2023cdatarsbssrfvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:cdata:arc:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:163538942
Shodan: http.favicon.hash:"163538942"
FOFA: icon_hash="163538942"

Source: ProjectDiscovery

References

5