CVE-2024-23788
 
Severity Score
9.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.
Vulnerabilidad de server-side request forgery en Energy Management Controller con servicios en la nube JH-RVB1 /JH-RV11 Ver.B0.1.9.1 y anteriores permite que un atacante no autenticado adyacente a la red envĂe una solicitud HTTP (GET) arbitraria desde el producto afectado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-01-22 CVE Reserved
- 2024-02-14 CVE Published
- 2025-03-19 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://jp.sharp/support/taiyo/info/JVNVU94591337_en.pdf | ||
https://jp.sharp/support/taiyo/info/JVNVU94591337_jp.pdf | ||
https://jvn.jp/en/vu/JVNVU94591337 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sharp Corporation Search vendor "Sharp Corporation" | Energy Management Controller With Cloud Services Search vendor "Sharp Corporation" for product "Energy Management Controller With Cloud Services" | * | - |
Affected
| ||||||
Sharp Search vendor "Sharp" | Jh-rv11 Firmware Search vendor "Sharp" for product "Jh-rv11 Firmware" | * | - |
Affected
| ||||||
Sharp Search vendor "Sharp" | Jh-rvb1 Firmware Search vendor "Sharp" for product "Jh-rvb1 Firmware" | * | - |
Affected
|