A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 09 Jan 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall. | |
Weaknesses | CWE-918 | |
References |
|
MITRE
Status: PUBLISHED
Assigner: sonicwall
Published: 2025-01-09T06:58:40.573Z
Updated: 2025-01-09T15:03:52.395Z
Reserved: 2024-11-22T09:54:04.964Z
Link: CVE-2024-53705
Vulnrichment
Updated: 2025-01-09T15:03:44.601Z
NVD
Status : Received
Published: 2025-01-09T07:15:27.363
Modified: 2025-01-09T15:15:18.800
Link: CVE-2024-53705
Redhat
No data.