CVE-2020-24548
Summary
| CVE | CVE-2020-24548 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-26 19:15:00 UTC |
| Updated | 2020-09-01 17:47:00 UTC |
| Description | Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ericom | Access Server | 9.2.0 | All | All | All |
| Application | Ericom | Access Server | 9.2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ericom Access Server 9.2.0 Server-Side Request Forgery ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Ericom Access Server v9.2.0 / Server Side Request Forgery / CVE-2020-24548 - YouTube | MISC | www.youtube.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.