An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Inim
Subscribe
|
Smartliving 10100l
Subscribe
Smartliving 10100l Firmware
Subscribe
Smartliving 10100lg3
Subscribe
Smartliving 10100lg3 Firmware
Subscribe
Smartliving 1050
Subscribe
Smartliving 1050 Firmware
Subscribe
Smartliving 1050g3
Subscribe
Smartliving 1050g3 Firmware
Subscribe
Smartliving 505
Subscribe
Smartliving 505 Firmware
Subscribe
Smartliving 515
Subscribe
Smartliving 515 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-14768 | An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T14:30:33.702Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-22002
No data.
Status : Modified
Published: 2021-04-29T15:15:10.537
Modified: 2024-11-21T05:13:00.383
Link: CVE-2020-22002
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD