CVE-2024-56524
The Radware Cloud Web Application Firewall is vulnerable to filter bypass by multiple means. The first is via specially crafted HTTP request and the second being insufficient validation of user-supplied input when processing a special character. An attacker with knowledge of these vulnerabilities can perform additional attacks without interference from the firewall. The Radware Cloud Web Application Firewall can be bypassed by means of a crafted HTTP request. If random data is included in the HTTP request body with a HTTP GET method, WAF protections may be bypassed. It should be noted that this evasion is only possible for those requests that use the HTTP GET method. Another way the Radware Cloud WAF can be bypassed is if an attacker adds a special character to the request. The firewall fails to filter these requests and allows for various payloads to reach the underlying web application.
EPSS 0.30% · 53.5th percentile
Risk Scores
Timeline
- May 8, 2025 PoC Published
- May 12, 2025 CVE Published
- May 12, 2025 Coalition ESS Score
- May 12, 2025 Coalition ESS Score
- May 12, 2025 PoC Published
- May 12, 2025 CVE Updated
- May 13, 2025 EPSS Score
- May 13, 2025 PoC Published
- May 24, 2025 EPSS Score
- Jun 5, 2025 EPSS Score
- Jun 16, 2025 EPSS Score
- Jun 28, 2025 EPSS Score