An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality
Published Apr 29, 2021
7.5
HIGHCVSS 3.1
EPSS 1.35%
Description
An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host.
Affected products
No data.
Configuration 1
- n/a
Running on/with
- n/a
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
- n/a
Running on/with
- n/a
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
- n/a
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-14768 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/172839 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5545.php x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-14768 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/172839 | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5545.php | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.