Vulnerability Description
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Havocframework | Havoc | - |
Related Weaknesses (CWE)
References
- https://blog.chebuya.com/posts/server-side-request-forgery-on-havoc-c2/ExploitThird Party Advisory
FAQ
What is CVE-2024-41570?
CVE-2024-41570 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.
How severe is CVE-2024-41570?
CVE-2024-41570 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-41570?
Check the references section above for vendor advisories and patch information. Affected products include: Havocframework Havoc.