Junglewise Threat Intelligence

CVE-2024-55399: 4C Strategies Exonaut SSRF

CVE-2024-55399 · Severity: medium · CVSS 6.5 · Published 2025-08-06

Technologies: 4C Strategies Exonaut.

Executive brief

4C Strategies Exonaut, a platform used for crisis management and organizational resilience, contains a vulnerability that allows for Server-Side Request Forgery (SSRF). An attacker could exploit this to make the server perform unauthorized requests to internal or external systems. This could lead to unauthorized data access or the ability to bypass internal network security controls.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in 4C Strategies Exonaut versions prior to 21.6.2.1-1 and version 22.0. The flaw allows a remote attacker to send crafted requests from the vulnerable server to other internal or external resources. This is classified as CWE-918 and can be exploited without authentication over the network. Successful exploitation may allow an attacker to probe internal network services or access sensitive information that is otherwise restricted. The issue has been addressed in versions 21.6.2.1-1 and 22.1.

Affected products

  • 4C Strategies Exonaut before 21.6.2.1-1, 22.0

Timeline

  • 2025-08-05: disclosed: Vulnerability discovered by Justin Hocquel
  • 2025-08-06: advisory: NVD publication date

References