PT-2026-58047 · Unknown+1 · Sustainable Irrigation Platform+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Sustainable Irrigation Platform (SIP) versions prior to 5.2.17
Description
A server-side request forgery (SSRF) issue exists when the optional Node-RED plugin is installed. Unauthenticated attackers can force the device to issue arbitrary blind HTTP requests to internal or external hosts by providing a malicious callback URL. This is possible due to a lack of destination validation and the use of the default passphrase
opendoor.Recommendations
Update Sustainable Irrigation Platform (SIP) to version 5.2.17 or later.
Change the default passphrase
opendoor to a secure one.
Disable the Node-RED plugin if it is not required.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node-Red
Sustainable Irrigation Platform