Server-Side Request Forgery (SSRF) in SonicOS - CVE-2024-53705
Published: January 8, 2025 / Updated: January 10, 2025
SonicOS
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input in the SonicOS SSH management interface. A remote attacker can establish a TCP connection to an IP address on any port when the user is logged in to the firewall.