MEDIUM
Server-Side Request Forgery Vulnerability in Haivision Products
Published Feb 28, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.35%
Description
Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need for credentials. An attacker could compromise an internal server and retrieve requests sent by other users.
Affected products
-
- Version all versionsStatusaffectedConstraints-
- Version
-
- Version all versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Haivision | Aviwest Manager | unaffected |
| ||||||
| Haivision | Aviwest Streamhub | unaffected |
|
-
- Version 0StatusaffectedConstraints<=*
- Version
-
- Version 0StatusaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Haivision | Aviwest Manager | n/a |
| ||||||
| Haivision | Aviwest Streamhub | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-17683 Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vulnerability-haivision-products Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-17683 | Advisory | |
| https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vulnerability-haivision-products | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Feb 28, 2024
Updated Aug 2, 2024
Reserved Feb 28, 2024
Link CVE-2024-1965
CISA Vulnrichment
Updated Aug 2, 2024
ENISA EUVD
EUVD-2024-17683 Assigner INCIBE
Published Feb 28, 2024
Updated Aug 2, 2024
Exploited since n/a
Link EUVD-2024-17683