S4E just found a high-severity finding from ssl robot vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-45968 Scanner

CVE-2021-45968 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Pascom Cloud Phone System

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-45968
7.5
CVSS

An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Pascom Cloud Phone System is a communication platform widely used by businesses in various industries. It provides advanced features such as VoIP calling, video conferencing, call recording, and messaging to streamline communication processes within organizations. The platform aims to simplify and enhance communication, resulting in better collaboration and productivity among employees.

Recently, a critical vulnerability was discovered in Pascom Cloud Phone System (prior to version 7.20.x) that could potentially compromise the security of the entire system. The vulnerability, identified as CVE-2021-45968, allows an attacker to perform Server-Side Request Forgery (SSRF) attacks. In simpler terms, SSRF attacks enable attackers to access internal network resources and carry out malicious activities such as stealing confidential data, launching further attacks, or even compromising the entire network.

If an attacker exploits this vulnerability, the results could be catastrophic for organizations utilizing Pascom Cloud Phone System. They could gain unauthorized access to sensitive business data, hijack user accounts, and cause severe damage to the business's reputation. Additionally, attackers can spread malware or ransomware onto the internal networks, resulting in heavy financial losses and disruptions to business operations.

In conclusion, the Pascom Cloud Phone System is a valuable tool for businesses in enhancing their overall communication processes. However, the presence of the CVE-2021-45968 vulnerability in the platform poses a significant risk to organizations. It is crucial for businesses to take necessary precautions to prevent potential attacks and safeguard their digital assets. By using the advanced features of the s4e.io platform, businesses can find all the tools and resources they need to strengthen their security posture and protect against such vulnerabilities.

 

REFERENCES

Solution Advice

To safeguard their digital assets against the CVE-2021-45968 vulnerability in Pascom Cloud Phone System, organizations can take these precautions:

  • Install patches and updates provided by Pascom to fix the vulnerability.
  • Restrict network traffic to and from the backend Tomcat server to prevent unauthorized access.
  • Deploy firewalls, intrusion detection systems, and other security measures to detect and mitigate SSRF attacks.
  • Conduct regular security assessments to proactively identify vulnerabilities and security gaps.
  • Train employees on how to detect and prevent SSRF attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.