CVE-2024-6922
Server-Side Request Forgery in Automation 360
Record summary
CVE-2024-6922 has a selected CVSS score of 6.9 (medium); EIP currently links 1 Nuclei template.
Description
Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80) can trigger arbitrary web requests from the server.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Automation 360Browse Automationanywhere / Automation 360Default status: unaffected | CVE List | 21 to ≤ 32 | affected |
Nuclei templates
1ProjectDiscoveryHIGHAutomation Anywhere Automation 360 - Server-Side Request Forgery
Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component.
Impact
An attacker with unauthenticated access to the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80) can trigger arbitrary web requests from the server.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
Source: ProjectDiscovery