PoC Index

CVE-2022-40305

CRITICAL 9.8EPSS 1.3%

A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.26% chance of exploitation in the next 30 days, 68th percentile
Published
2022-09-09
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related