CVE-2023-39854: SSRF
Published Oct 9, 2023
·Updated
The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/getccurl url parameter. There can be resultant SSRF.
Affected Software
1 affected component
ATX Ucrypt<=3.5
Event History
Oct 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-39854.
2
What is the severity of CVE-2023-39854?
The severity of CVE-2023-39854 is medium (6.5).
3
What is the affected software for CVE-2023-39854?
The affected software for CVE-2023-39854 is ATX Ucrypt version up to and including 3.5.
4
How does the vulnerability in ATX Ucrypt occur?
The vulnerability in ATX Ucrypt allows authenticated users (or attackers using default credentials) to include files via a URL.
5
Is there a fix available for CVE-2023-39854?
There may be a fix available for CVE-2023-39854, it is recommended to check with the vendor or refer to the provided reference for more information.