Aller au contenu

Fiche vulnérabilité

CVE-2022-40305 : faille critique canto canto (CVSS 9.8)

Description

A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
9 sept. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • canto canto

Références

Rechercher une autre vulnérabilité dans la base CVE