Vulnerabilities > CVE-2024-1965 - Server-Side Request Forgery (SSRF) vulnerability in Haivision Maanager and Streamhub

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
haivision
CWE-918

Summary

Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need for credentials. An attacker could compromise an internal server and retrieve requests sent by other users.

Vulnerable Configurations

Part Description Count
Application
Haivision
2

Common Weakness Enumeration (CWE)