Impact
The vulnerability is a Server‑Side Request Forgery located in the /ocsreports/?function=tele_activate endpoint of Ocsreports. An authenticated operator can supply arbitrary values for the HTTPS_SERV and FILE_SERV parameters, and the server then makes outbound HTTP or HTTPS requests using those values. This allows the attacker to force the OCS Inventory server to contact internal network services or cloud metadata endpoints. The CVE is identified as CWE‑918. Based on the description, it is inferred that an attacker could collect sensitive data from internal resources, but no explicit statement of such exploitation is made in the official description.
Affected Systems
All releases of Ocsreports older than 2.12.6 are affected. The vulnerability was addressed in version 2.12.6, which was released by the OCS Inventory NG team. The affected product is the Ocsreports component of OCS Inventory NG, distributed by OCS Inventory NG and commonly used in enterprise asset‑management environments.
Risk and Exploitability
The CVSS score of 7.1 signifies a high severity flaw, though the EPSS score is not available, so the likelihood of exploitation is currently uncertain. The vulnerability requires authenticated operator privileges, which means the attacker must have insider or compromised credentials. The description notes that the server can reach internal resources or cloud metadata endpoints; based on this, it is inferred that an attacker could potentially use the SSRF to gather sensitive information or assist in lateral movement, but such effects are not explicitly stated in the advisory. The vulnerability is not listed in CISA’s KEV catalog, indicating no reported instances as of the data provided.
OpenCVE Enrichment