CVE-2024-6922 is a Server-Side Request Forgery (SSRF) vulnerability affecting Automation Anywhere Automation 360 versions v21-v32. An unauthenticated attacker can exploit this flaw via the Control Room HTTPS or HTTP service to trigger arbitrary web requests from the server. Rated with a CVSS score of 6.9 (Medium) and a FAUCET Risk Score of 97/100, this vulnerability has a high EPSS score, indicating a significant likelihood of exploitation. While there is no evidence of active exploitation in the wild or KEV listing, a Nuclei template for this high-severity vulnerability exists, suggesting potential for exploit development and use.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 21, <= 32CPE match | cpe:2.3:a:automationanywhere:automation_360:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.