CVE-2019-25251
MEDIUMDescription
Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary destinations.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| teradek | vidiu_pro_firmware |
| teradek | vidiu_pro_firmware |
| teradek | vidiu_pro_firmware |
| teradek | vidiu_pro |
| teradek | vidiu_firmware |
| teradek | vidiu_firmware |
| teradek | vidiu_firmware |
| teradek | vidiu |
| teradek | vidiu_mini_firmware |
| teradek | vidiu_mini_firmware |
| teradek | vidiu_mini_firmware |
| teradek | vidiu_mini |
References
Frequently Asked Questions
What is CVE-2019-25251? +
How severe is CVE-2019-25251? +
What products are affected by CVE-2019-25251? +
How do I check if I'm vulnerable to CVE-2019-25251? +
Related Vulnerabilities
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI …
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate …
MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side …
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) …
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary …
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server …