CVE-2024-45317: SSRF
Published Oct 11, 2024
·Updated
A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.
Affected Software
1 affected component
SMA SMA1000 appliance firmware<=12.4.3-02676
Event History
Oct 11, 2024
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45317?
CVE-2024-45317 has a high severity rating due to its potential for exploitation by remote, unauthenticated attackers.
2
How do I fix CVE-2024-45317?
To fix CVE-2024-45317, upgrade the SMA1000 appliance firmware to version 12.4.3-02677 or later.
3
What type of vulnerability is CVE-2024-45317?
CVE-2024-45317 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
4
Who is affected by CVE-2024-45317?
Users of SMA1000 appliance firmware versions 12.4.3-02676 and earlier are affected by CVE-2024-45317.
5
Can CVE-2024-45317 be exploited remotely?
Yes, CVE-2024-45317 can be exploited remotely by an unauthenticated attacker.