Home
MEDIUM: 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:NDefault status
unaffected
8.3 (custom)
affected
Description
A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of host request header.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
8.3 (custom)
References
seclists.org/fulldisclosure/2025/Jul/10
download.schneider-electric.com/...Name=SEVD-2025-189-01.pdf