Περιγραφή
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed. Attackers can exploit the lack of destination validation and the default passphrase -opendoor- to send blind HTTP requests to arbitrary internal or external hosts not otherwise directly accessible.
CVSS 6.5EPSS 0.261%Κίνδυνος 0.67
Προβολή πηγής- Δημοσίευση
- 2026-07-14 15:17:06
- Επηρεαζόμενες εκδόσεις
- <=5.2.16
- Τύπος
- Υλικολογισμικό
- Διάνυσμα
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L