Impact
The vulnerability is a Server Side Request Forgery (SSRF) flaw that allows an attacker to instruct the vulnerable application to make arbitrary HTTP requests to internal or external systems. An exploited SSRF can enable information disclosure, internal network reconnaissance, or further lateral movement, potentially affecting the confidentiality and integrity of internal resources. The CVSS score of 7.2 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present, yet the existence of the flaw warrants remediation.
Affected Systems
Johnson Controls CCure 9000 and Victor application server, versions 2.9 through 3.0, are affected by this SSRF vulnerability.
Risk and Exploitability
The CVSS score of 7.2 reflects a significant risk if the flaw is exploitable. The EPSS score of < 1% and absence of listing in CISA KEV indicate that, while exploitation is currently unlikely, the vulnerability remains a potential threat. The description does not detail authentication requirements; however, the typical SSRF attack vector is inferred to be an accessible endpoint allowing an attacker to craft requests, thereby forcing the server to reach arbitrary URLs, including internal resources. No official workaround is provided by the vendor.
OpenCVE Enrichment