CVE-2020-24548: Ericom Access Server
Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to inform the attacker about closed ports.
Affected products
- Ericom Access Server: version 9.2.0 only
Published 2020-08-26. Last modified 2026-06-17.