CVE-2023-39854
Last modified
CVE-2023-39854 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Atx | Ucrypt | <= 3.5 |
References
- https://wiki.notveg.ninja/blog/CVE-2023-39854/Mitigation, Third Party Advisory
- https://wiki.notveg.ninja/blog/CVE-2023-39854/Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-39854?
How severe is CVE-2023-39854?
How do I fix CVE-2023-39854?
Are you affected by CVE-2023-39854?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
