Executive brief
Bottinelli Informatica Vedo Suite, a software solution likely used for video management or surveillance, contains a security flaw that allows authorized users to redirect the server's web requests. An attacker with basic login credentials could use this to probe internal network resources that are otherwise hidden from the public internet. This could lead to the exposure of sensitive internal data or further attacks against the organization's private infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Bottinelli Informatica Vedo Suite version 2024.17. The flaw is located within the '/api_vedo/video/preview' endpoint, which fails to properly validate the 'file' URL parameter. A remote authenticated attacker can exploit this by providing a malicious URL, causing the server to initiate HTTP requests to arbitrary internal or external paths. This can be used to bypass network segmentation, perform internal port scanning, or access sensitive metadata services. A proof-of-concept exploit has been identified in public repositories.
Affected products
- Bottinelli Informatica Vedo Suite 2024.17
Timeline
- 2025-08-06: advisory: Initial disclosure of CVE-2025-51058
- 2025-08-07: other: CISA-ADP enrichment and CVSS scoring added