Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need for credentials. An attacker could compromise an internal server and retrieve requests sent by other users.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vulnerability-haivision-products | Third Party Advisory |
| https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vulnerability-haivision-products | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
10 Apr 2025, 19:26
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CWE | CWE-918 |
04 Mar 2025, 12:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:haivision:streamhub:*:*:*:*:*:*:*:* cpe:2.3:a:haivision:maanager:*:*:*:*:*:*:*:* |
|
| References | () https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vulnerability-haivision-products - Third Party Advisory | |
| First Time |
Haivision streamhub
Haivision Haivision maanager |
|
| CWE |
28 Feb 2024, 14:06
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-02-28 13:15
Updated : 2025-04-10 19:26
NVD link : CVE-2024-1965
Mitre link : CVE-2024-1965
JSON object : View
Products Affected
haivision
- streamhub
- maanager
CWE
CWE-918
Server-Side Request Forgery (SSRF)
