Automation 360 v32 and lower versions are vulnerable to medium-severity, blind Server-Side Request Forgery in a web API component. An attacker with unauthenticated privilege can access the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80), can trigger arbitrary web requests from the server.
Known Issue: Server Side Request Forgery (SSRF) Medium Severity Vulnerability CVE-2024-6922 in Control Room
This topic has been closed for comments
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.