CVE-2024-23788: SSRF
Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23788?
CVE-2024-23788 is classified as a high severity vulnerability due to its potential for server-side request forgery.
How do I fix CVE-2024-23788?
To fix CVE-2024-23788, update the Energy Management Controller firmware to a version later than B0.1.9.1.
Who is affected by CVE-2024-23788?
CVE-2024-23788 affects users of Sharp JH-RVB1 and JH-RV11 firmware versions B0.1.9.1 and earlier.
What type of attack does CVE-2024-23788 allow?
CVE-2024-23788 allows an unauthenticated attacker to send arbitrary HTTP GET requests through the affected devices.
Is CVE-2024-23788 exploited remotely?
CVE-2024-23788 can be exploited by attackers who are on the same network as the vulnerable device.