Impact
A flaw in the isPrivateOrRestrictedIP function within the web_fetch component of Sipeed PicoClaw allows an attacker to cause the server to make HTTP requests to arbitrary addresses, including internal services. This server‑side request forgery (SSRF) can expose internal resources, enable credential harvesting, or facilitate lateral movement within the network. The flaw exists in versions up to 0.2.9 and is mitigated by applying the public patch provided by the vendor.
Affected Systems
Sipeed PicoClaw versions 0.2.9 and earlier are affected. The vulnerability resides in the file pkg/tools/integration/web.go of the web_fetch component. Version 0.2.9 or earlier should be considered vulnerable; newer releases are presumed patched.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA KEV, but an exploit is publicly available. Attackers can initiate it remotely, making the risk moderate for deployments with unrestricted outbound network access.
OpenCVE Enrichment