Vulnerability Description
Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need for credentials. An attacker could compromise an internal server and retrieve requests sent by other users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haivision | Maanager | All versions |
| Haivision | Streamhub | All versions |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vThird Party Advisory
FAQ
What is CVE-2024-1965?
CVE-2024-1965 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need f...
How severe is CVE-2024-1965?
CVE-2024-1965 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-1965?
Check the references section above for vendor advisories and patch information. Affected products include: Haivision Maanager, Haivision Streamhub.