← Retour à la recherche de CVE

CVE-2026-58478

Sustainable Irrigation Platform (SIP)

Description

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when the optional Node-RED plugin is installed. Attackers can exploit the lack of destination validation and the default passphrase -opendoor- to send blind HTTP requests to arbitrary internal or external hosts not otherwise directly accessible.

CVSS 6.5EPSS 0.261%Risque 0.67
Voir la source
Publication
2026-07-14 15:17:06
Versions concernées
<=5.2.16
Type
Micrologiciel
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L