← Back to browse · API

CVE-2024-41570

Severity
CRITICAL
CVSS
9.8
EPSS
0.02909
Risk score
40.22
CISA KEV
No
PoC
No
Published
2024-08-09
Modified
2024-08-09
First seen
2026-08-07
Aliases
EUVD-2024-39077, GHSA-5MCQ-H782-4VG7
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-39077

Description

An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.

References