vendor:
Selea Targa IP OCR-ANPR Camera
by:
LiquidWorm
8.8
CVSS
HIGH
Server-Side Request Forgery (SSRF)
918
CWE
Product Name: Selea Targa IP OCR-ANPR Camera
Affected Version From: BLD201113005214
Affected Version To: BLD191021180140
Patch Exists: YES
Related CWE: N/A
CPE: h:selea:targa_ip_ocr-anpr_camera
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2020
Selea Targa IP OCR-ANPR Camera Unauthenticated SSRF
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in the Selea ANPR camera within several functionalities. The application parses user supplied URLs and makes requests to them without any validation. This allows an attacker to make requests to internal services, such as the camera's web server, and possibly gain access to sensitive information.
Mitigation:
Upgrade to the latest version of the Selea ANPR camera firmware.