Skip to main content
Sticky

Known Issue: Server Side Request Forgery (SSRF) Medium Severity Vulnerability CVE-2024-6922 in Control Room

  • 2 August 2024
  • 0 replies
  • 107 views

Automation 360 v32 and lower versions are vulnerable to medium-severity, blind Server-Side Request Forgery in a web API component. An attacker with unauthenticated privilege can access the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80), can trigger arbitrary web requests from the server.
 

Learn more in this Knowledge Base article.

This topic has been closed for comments