S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 2, 2024

CVE-2024-6922 Scanner

CVE-2024-6922 scanner - Server-Side Request Forgery (SSRF) vulnerability in Automation Anywhere Automation 360

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6922
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80) can trigger arbitrary web requests from the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Automation 360by Automationanywhere
21
Updated Aug 22, 2026View on NVD →
Detail

Automation Anywhere Automation 360 is a popular Robotic Process Automation (RPA) platform used by organizations worldwide to automate various business processes. It is employed by both IT and business professionals to streamline repetitive tasks and integrate workflows. The platform provides a web-based interface to design, execute, and manage automation tasks. Its Control Room component is crucial for managing and deploying bots across an organization. The platform is widely adopted in sectors such as finance, healthcare, and manufacturing.

The vulnerability in Automation Anywhere Automation 360 is a Server-Side Request Forgery (SSRF) flaw. It allows an attacker to manipulate the server into making arbitrary web requests, potentially exposing internal services or accessing sensitive data. The SSRF vulnerability can be exploited without authentication, making it particularly dangerous. This flaw is found in a web API component of the platform.

The SSRF vulnerability is located in the Automation 360 Control Room’s web API, where the /v1/proxy/test endpoint is vulnerable. An attacker can craft a specially crafted HTTP POST request that includes a malicious saasUrl parameter. When the server processes this request, it will attempt to access the provided URL, allowing the attacker to force the server to send requests to internal or external services. The vulnerability is confirmed by detecting DNS resolution attempts triggered by the server when interacting with attacker-controlled domains.

If exploited, this vulnerability can have severe consequences. An attacker could gain unauthorized access to internal services, potentially leading to data breaches, internal network scanning, or further attacks on other systems within the organization. The attacker could also exploit this vulnerability to bypass security controls, access sensitive information, or disrupt operations by targeting critical services.

By using the S4E platform, you can protect your organization against critical vulnerabilities like CVE-2024-6922. Our comprehensive scanning service detects and reports vulnerabilities in your digital assets, helping you secure your systems before attackers can exploit them. Join our platform to benefit from detailed insights, remediation guidance, and continuous monitoring to keep your environment safe from emerging threats.

References:

Solution Advice
  • Apply patches or updates provided by Automation Anywhere to fix the SSRF vulnerability.
  • Restrict access to the vulnerable API endpoints and limit network exposure of the Control Room interface.
  • Implement proper input validation and sanitization on all parameters that are used in web requests.
  • Monitor server logs for suspicious activities that may indicate SSRF attempts.
  • Consider deploying a Web Application Firewall (WAF) to block malicious requests targeting known vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.