Vulnerabilities > CVE-2020-24548 - Server-Side Request Forgery (SSRF) vulnerability in Ericom Access Server 9.2.0

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ericom
CWE-918

Summary

Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports.

Vulnerable Configurations

Part Description Count
Application
Ericom
1

Common Weakness Enumeration (CWE)