Skip to main content

Automation 360 v32 and lower versions are vulnerable to medium-severity, blind Server-Side Request Forgery in a web API component. An attacker with unauthenticated privilege can access the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80), can trigger arbitrary web requests from the server.
 

Learn more in this Knowledge Base article.