ZeroHour

CVE-2022-40305

PoC
CVSS 3.1
9.8 critical
EPSS
2%p73
Published
()
Modified
Description

A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form.

Vendors
canto
Products
canto
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.