Server Side Request Forgery in OpenBMCS 2.4 by OpenBMCS
CVE-2021-47703
Key Information:
Badges
What is CVE-2021-47703?
OpenBMCS version 2.4 is susceptible to an unauthenticated Server Side Request Forgery (SSRF) vulnerability. This flaw allows attackers to manipulate the application into making unauthorized HTTP requests to any specified external domain via the 'ip' parameter. Consequently, this can enable attackers to bypass firewall protections and perform network and service enumeration on the internal network, potentially leading to the hijacking of active sessions. It is critical for users to be aware of this vulnerability and take preventive measures to secure their systems.
Affected Version(s)
OpenBMCS 2.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
