Impact
The updated vulnerability description indicates that the Sef – AI Chatbot Platform's tool runner API is vulnerable to Server‑Side Request Forgery, allowing an attacker to instruct the server to make HTTP requests to arbitrary destinations. This flaw can expose internal services, leak sensitive data, and provide a path to otherwise inaccessible networks. The weakness is a CWE‑918 type.
Affected Systems
HAVELSAN Inc.’s Sef – AI Chatbot Platform, for all versions earlier than 2.1. The API endpoint responsible for tool execution is exposed publicly and is the source of the SSRF vulnerability.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity flaw, and the EPSS score is 0.00274, indicating an extremely low exploitation probability. The platform is not listed in the CISA KEV catalog. The likely attack vector is an externally‑initiated request to the tool runner endpoint, exploiting the lack of validation on target URLs. Attacks would require an attacker’s ability to reach the platform but do not need privileged internal access.
OpenCVE Enrichment