Ericom Access Server 9.2.0 Server-Side Request Forgery
Posted by deepcore on August 26, 2020 – 7:03 am
Ericom Access Server allows attackers to initiate SSRF requests making outbound connections to arbitrary hosts and TCP ports. Attackers, who can reach the AccessNow server can target internal systems that are behind firewalls that are typically not accessible. This can also be used to target third-party systems from the AccessNow server itself. Version 9.2.0 is affected.
Post a reply
You must be logged in to post a comment.