CVE-2019-25251
Teradek VidiU Pro 3.0.3 Server-Side Request Forgery via RTMP Settings
Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary destinations.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
Produtos afetados
Teradek, LLC · VidiU ProQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →