Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need for credentials. An attacker could compromise an internal server and retrieve requests sent by other users.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vulnerability-haivision-products | Third Party Advisory |
https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vulnerability-haivision-products | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
10 Apr 2025, 19:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-vulnerability-haivision-products - Third Party Advisory | |
First Time |
Haivision maanager
Haivision streamhub Haivision |
|
CPE | cpe:2.3:a:haivision:streamhub:*:*:*:*:*:*:*:* cpe:2.3:a:haivision:maanager:*:*:*:*:*:*:*:* |
Information
Published : 2024-02-28 13:15
Updated : 2025-04-10 19:26
NVD link : CVE-2024-1965
Mitre link : CVE-2024-1965
CVE.ORG link : CVE-2024-1965
JSON object : View
Products Affected
haivision
- maanager
- streamhub
CWE
CWE-918
Server-Side Request Forgery (SSRF)