Vulnerability Details CVE-2020-24548
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 74.1%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2020-24548
-
cpe:2.3:a:ericom:access_server:9.2.0