CVE-2024-56523

CRITICAL

Radware Cloud WAF <2025-05-07 - Auth Bypass

Title source: llm
STIX 2.1

Description

Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method.

Scores

CVSS v3 9.1
EPSS 0.0030
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-444
Status published
Products (1)
radware/cloud_waf < 2025-05-07
Published May 12, 2025
Tracked Since Feb 18, 2026