CVE-2022-39055

RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-6616-9092f-1.html Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:changingtec:rava_certificate_validation_system:3:*:*:*:*:*:*:*

History

20 Oct 2022, 15:07

Type Values Removed Values Added
References (MISC) https://www.twcert.org.tw/tw/cp-132-6616-9092f-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-6616-9092f-1.html - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:changingtec:rava_certificate_validation_system:3:*:*:*:*:*:*:*
CWE CWE-918
First Time Changingtec rava Certificate Validation System
Changingtec

18 Oct 2022, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-18 06:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-39055

Mitre link : CVE-2022-39055

CVE.ORG link : CVE-2022-39055


JSON object : View

Products Affected

changingtec

  • rava_certificate_validation_system
CWE
CWE-918

Server-Side Request Forgery (SSRF)